DPA Agreement Template for New Zealand
Generate a bespoke document
What is a DPA Agreement?
A Data Processing Agreement (DPA) is required whenever an organization (the data controller) engages another organization (the data processor) to process personal data on its behalf. This document is essential for compliance with New Zealand's Privacy Act 2020 and is particularly crucial in the current digital landscape where data processing activities are increasingly outsourced. The DPA Agreement establishes clear accountability and transparency in data handling operations, defining specific responsibilities for both parties, security requirements, breach notification procedures, and data subject rights management. It becomes especially important when dealing with sensitive personal information, cross-border data transfers, or when engaging multiple sub-processors. The agreement helps organizations demonstrate their commitment to data protection and privacy compliance while managing risks associated with third-party data processing.
Trusted by high-performance teams
About the DPA Agreement
When your organization engages third-party service providers to handle personal data, you need a comprehensive Data Processing Agreement (DPA) to comply with New Zealand's privacy laws. This contract establishes the legal relationship between you as the data controller and your service provider as the data processor, ensuring both parties understand their obligations under the Privacy Act 2020.
When do you need this document?
You need a DPA Agreement whenever you engage external organizations to process personal data on your behalf. This includes cloud storage providers, payroll services, customer relationship management platforms, marketing agencies handling customer data, and IT support companies accessing your systems. The agreement is essential when outsourcing any business function that involves handling personal information, whether it's employee records, customer databases, or sensitive business data. You also need this document when engaging sub-processors or when transferring data across borders, particularly to countries without adequate privacy protections.
Key legal considerations
Your DPA Agreement must clearly define the scope and purpose of data processing, specifying what types of personal data will be processed and for what purposes. The contract should include robust security measures that align with the Privacy Act 2020's requirement for reasonable security safeguards. Data breach notification procedures are crucial, requiring your processor to notify you immediately of any privacy breaches so you can meet the mandatory 72-hour reporting requirement to the Privacy Commissioner. The agreement must address data subject rights, ensuring individuals can exercise their rights to access, correct, or delete their personal information. Cross-border data transfer provisions are essential if data will be sent overseas, requiring adequate privacy protections in the receiving country or appropriate safeguards like binding corporate rules or standard contractual clauses.
Legal requirements in New Zealand
Under the Privacy Act 2020, your DPA Agreement must ensure compliance with the 13 privacy principles, particularly principles relating to collection, use, disclosure, security, and retention of personal information. The contract must specify that the processor will only process personal data on your documented instructions and will implement appropriate technical and organizational security measures. You must ensure the processor has adequate systems for handling privacy requests and complaints from data subjects. The agreement should address data retention and deletion requirements, specifying how long data will be held and secure deletion procedures. For international data transfers, you must ensure the receiving country has privacy laws that are substantially similar to New Zealand's or implement alternative safeguards. The processor must assist with privacy impact assessments when required and provide evidence of compliance through regular audits or certifications.
GOVERNING LAW
Applicable law
This DPA Agreement is drafted to comply with New Zealand law. Key legislation includes:
Contract and Commercial Law Act 2017: Provides the legal framework for electronic transactions and general contract law principles in New Zealand
Unsolicited Electronic Messages Act 2007: Relevant for data processing activities involving electronic communications and marketing
Fair Trading Act 1986: Ensures fair trading practices and could be relevant for commercial aspects of data processing relationships
GDPR Considerations: While not NZ legislation, consideration should be given to GDPR if the data processing involves EU residents or data transfers to/from the EU
APEC Privacy Framework: Regional privacy framework that influences New Zealand's approach to cross-border data transfers within the Asia-Pacific region
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

