Data Processing Addendum Template for New Zealand

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Data Processing Addendum?

The Data Processing Addendum (DPA) is an essential legal document used when an organization (the data controller) engages another party (the data processor) to process personal information on its behalf. This document is particularly crucial in the New Zealand context, where the Privacy Act 2020 imposes strict requirements on organizations handling personal information. The DPA supplements the main service agreement between parties and specifically addresses data protection obligations, security requirements, and compliance measures. It should be used whenever a service provider will have access to or process personal information on behalf of another organization, regardless of the industry or scale of processing. The document includes crucial provisions about data security, breach notification, sub-processor engagement, and international data transfers, ensuring compliance with New Zealand privacy laws while also considering international data protection standards.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

New Zealand

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Processing Addendum

A Data Processing Addendum (DPA) is a critical legal document that supplements your main service agreement when engaging third-party processors to handle personal information on your behalf. Under New Zealand's Privacy Act 2020, you have specific obligations when sharing personal data with service providers, making a properly drafted DPA essential for legal compliance and risk management.

When do you need this document?

You need a Data Processing Addendum whenever you engage a service provider who will access, store, or process personal information as part of their services. This includes cloud storage providers, payroll processors, marketing agencies handling customer data, IT support companies accessing employee information, or any contractor who may encounter personal data during service delivery. The document is particularly important for international service providers, as it helps ensure compliance with both New Zealand privacy laws and overseas data protection requirements. Without a DPA, you may be in breach of your obligations under the Privacy Act 2020 and could face regulatory action or civil claims.

Key legal considerations

Your DPA must clearly define the scope and purpose of data processing, specifying what types of personal information will be processed and for what purposes. Security measures are crucial - the document should outline technical and organizational safeguards, including encryption requirements, access controls, and data retention policies. Breach notification procedures must be established, detailing how quickly the processor must notify you of any privacy breaches and what information must be provided. The agreement should address sub-processor arrangements, requiring your consent before engaging additional parties and ensuring they meet the same security standards. International data transfer provisions are essential if data may be processed or stored overseas, including adequate protection mechanisms and legal safeguards.

Legal requirements in New Zealand

Under the Privacy Act 2020, you remain accountable for personal information even when processed by third parties, making contractual protections vital. The Act requires that personal information be protected by reasonable security safeguards and processed only for lawful purposes. Your DPA must ensure the processor complies with the privacy principles, particularly around collection limitations, use restrictions, and security safeguards. Mandatory data breach notification requirements mean your agreement must establish clear reporting timelines and procedures. The processor must also cooperate with privacy impact assessments and respond to data subject requests. If processing involves consumer data, Fair Trading Act 1986 considerations around truthful representations become relevant. For electronic marketing data, compliance with the Unsolicited Electronic Messages Act 2007 may also be required.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it