Joint Controller Agreement Template for New Zealand

Generate a bespoke document

What is a Joint Controller Agreement?

This Joint Controller Agreement template is designed for use under New Zealand law when two or more organizations need to formalize their relationship as joint controllers of personal data. The document becomes necessary when multiple entities collaborate in determining the purposes and means of processing personal information, requiring clear allocation of responsibilities under the Privacy Act 2020. It addresses key aspects such as data protection compliance, security measures, breach notification procedures, and the handling of data subject rights. The agreement is particularly important in contexts where organizations share data processing activities, such as joint ventures, partnerships, or collaborative projects, and need to ensure compliance with New Zealand's privacy framework while maintaining transparent and efficient data processing operations.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

New Zealand

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Joint Controller Agreement

A Joint Controller Agreement is a specialized contract that formalizes the relationship between two or more organizations that jointly determine the purposes and means of processing personal information. Under New Zealand's Privacy Act 2020, when multiple entities share control over data processing decisions, they must clearly define their respective roles, responsibilities, and obligations to ensure compliance with privacy principles and maintain accountability for data protection.

When do you need this document?

You need a Joint Controller Agreement when your organization collaborates with other entities in ways that involve shared decision-making about personal data processing. Common scenarios include joint ventures between companies that share customer databases, research collaborations between universities and private organizations that collect participant data together, marketing partnerships where multiple brands jointly process customer information for promotional activities, and consortium arrangements where member organizations contribute and access shared datasets. The agreement becomes legally necessary whenever you and another organization jointly determine not just what personal information to collect, but how it will be used, stored, and shared.

Key legal considerations

Your Joint Controller Agreement must clearly allocate responsibilities under the Privacy Act 2020's information privacy principles. Key provisions should address how you'll handle data subject access requests, ensuring either controller can respond effectively without creating confusion or delays. The agreement must establish comprehensive security measures that both parties will implement, including technical safeguards and staff training requirements. Breach notification procedures are critical - you need clear protocols for how either party will notify the other, affected individuals, and the Privacy Commissioner within required timeframes. The agreement should also address data retention periods, ensuring both controllers apply consistent policies, and establish procedures for data transfers, particularly if either party plans to send personal information overseas. Consider including dispute resolution mechanisms and termination procedures that protect personal information when the joint relationship ends.

Legal requirements in New Zealand

Under the Privacy Act 2020, joint controllers have equal responsibility for compliance with all 13 information privacy principles, regardless of which party initially collected the personal information. You must ensure your agreement addresses cross-border data transfer requirements if either controller operates internationally or uses overseas service providers. The agreement should incorporate the Privacy Act's definition of personal information and align with the agency's guidance on joint controllers issued by the Privacy Commissioner. New Zealand's Contract and Commercial Law Act 2017 governs the agreement's formation and enforceability, requiring clear terms and mutual consideration. Fair Trading Act 1986 obligations may apply if your joint processing involves consumer-facing activities, requiring transparent and accurate representations about data handling practices. Consider Consumer Guarantees Act 1993 implications if your joint processing supports services provided to consumers, as this may create additional accountability requirements.

GOVERNING LAW

Applicable law

This Joint Controller Agreement is drafted to comply with New Zealand law. Key legislation includes:

Privacy Act 2020: New Zealand's primary privacy legislation that sets out the privacy principles, obligations for handling personal information, and cross-border data transfer requirements. This is crucial for defining the joint controllers' obligations and responsibilities.
Contract and Commercial Law Act 2017: Provides the legal framework for forming and enforcing contracts in New Zealand, which is essential for the validity and enforceability of the joint controller agreement.
Fair Trading Act 1986: Ensures fair trading practices and prohibits misleading conduct in trade. Relevant for transparency obligations and representations made in the agreement about data handling practices.
Consumer Guarantees Act 1993: May be relevant if the joint processing activities involve services to consumers, establishing certain guarantees and rights that cannot be contracted out of.
Electronic Transactions Act 2002: Relevant for electronic execution of the agreement and electronic communications between joint controllers, particularly important if the agreement is executed or managed digitally.
Unsolicited Electronic Messages Act 2007: Important if the joint processing activities involve electronic marketing or communications, setting out requirements for consent and opt-out mechanisms.
GDPR Considerations: While not NZ legislation, the EU General Data Protection Regulation should be considered if either party processes EU residents' data or has EU operations, as it has specific requirements for joint controller arrangements.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it

Ready to agree with confidence?
See Genie in action.