Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
DPA Data Processing Addendum
"I need a Data Processing Addendum for my cloud software company based in Sydney that will process customer data in both Australia and Singapore, with particular focus on cross-border data transfers and sub-processor requirements for implementation by March 2025."
1. Parties: Identification of the data controller (client) and data processor (service provider), including their registered addresses and company details
2. Background: Context of the DPA, reference to the main service agreement, and purpose of the data processing addendum
3. Definitions: Key terms used in the DPA, including 'Personal Information', 'Processing', 'Data Subject', 'Privacy Laws', etc.
4. Scope and Purpose of Processing: Detailed description of the data processing activities, types of personal information, and purposes for which data will be processed
5. Obligations of the Data Processor: Core responsibilities of the processor including processing only on documented instructions, confidentiality, security measures, and breach notification
6. Obligations of the Data Controller: Responsibilities of the controller including lawful basis for processing, accuracy of data, and providing documented instructions
7. Security Measures: Technical and organizational security measures required to protect personal information
8. Sub-processing: Conditions and requirements for engaging sub-processors, including notification and approval processes
9. Data Breach Notification: Procedures for handling and reporting data breaches in accordance with the Notifiable Data Breaches scheme
10. Cross-border Data Transfers: Requirements and safeguards for international data transfers under APP 8
11. Audit Rights: Controller's rights to audit the processor's compliance with the DPA
12. Term and Termination: Duration of the DPA and conditions for termination
13. Return or Deletion of Data: Obligations regarding personal information upon termination of services
1. Industry-Specific Compliance: Additional requirements for specific sectors (e.g., healthcare, finance) - include when processing sensitive or regulated data
2. Data Protection Impact Assessment: Procedures for conducting DPIAs - include when processing high-risk data or using new technologies
3. Special Categories of Data: Additional safeguards for sensitive information - include when processing health, biometric, or other sensitive data
4. Insurance Requirements: Specific insurance obligations - include when processing high-value or sensitive data
5. Disaster Recovery: Detailed disaster recovery and business continuity requirements - include for critical data processing services
6. Joint Controller Provisions: Specific provisions for joint controller arrangements - include when both parties determine processing purposes
1. Schedule 1 - Details of Processing: Detailed description of processing activities, categories of data subjects, types of personal information, and processing purposes
2. Schedule 2 - Technical and Organizational Security Measures: Specific security controls, standards, and measures implemented to protect personal information
3. Schedule 3 - Approved Sub-processors: List of authorized sub-processors and their processing activities
4. Schedule 4 - Cross-border Transfer Mechanisms: Details of mechanisms used for international data transfers and recipient countries
5. Appendix A - Data Breach Response Plan: Detailed procedures for identifying, reporting, and managing data breaches
6. Appendix B - Audit Requirements: Specific audit procedures, timelines, and requirements
Authors
APP
Australian Privacy Law
Authorised Person
Business Day
Business Hours
Commissioner
Confidential Information
Controller
Data Breach
Data Subject
Information Security Incident
Notifiable Data Breach
OAIC
Personal Information
Privacy Act
Privacy Laws
Processor
Processing
Representatives
Sensitive Information
Services
Security Measures
Sub-processor
Technical and Organisational Measures
Third Party
Cross-border Disclosure
Data Processing Services
Main Agreement
Permitted Purpose
Privacy Impact Assessment
Processing Instructions
Regulatory Authority
Required Information
Term
Scope of Processing
Processing Obligations
Data Protection
Security Requirements
Confidentiality
Sub-processing
Cross-border Transfers
Audit Rights
Data Breach Notification
Liability
Insurance
Indemnification
Term and Termination
Data Return and Deletion
Cooperation
Compliance with Laws
Notice
Assignment
Severability
Entire Agreement
Governing Law
Dispute Resolution
Force Majeure
Variation
Costs
Regulatory Compliance
Personnel Obligations
Records and Audit
Business Continuity
Technology and Software
Healthcare and Medical Services
Financial Services
Professional Services
Education
Retail and E-commerce
Telecommunications
Insurance
Legal Services
Cloud Services
Marketing and Advertising
Human Resources and Recruitment
Government and Public Sector
Manufacturing
Research and Development
Legal
Compliance
Information Security
Privacy
Information Technology
Risk Management
Procurement
Operations
Data Management
Corporate Governance
Chief Privacy Officer
Data Protection Officer
Chief Information Security Officer
Privacy Counsel
Compliance Manager
Information Security Manager
Legal Counsel
IT Director
Risk Manager
Operations Manager
Procurement Manager
Contract Manager
Chief Technology Officer
Privacy Manager
Chief Legal Officer
Chief Compliance Officer
Find the exact document you need
Personal Information Processing Agreement
An Australian law-governed agreement establishing terms for personal information processing between controllers and processors, ensuring compliance with the Privacy Act 1988 and APPs.
DPA Data Processing Addendum
An Australian-law compliant agreement that establishes terms for processing personal information under the Privacy Act 1988 and APPs, defining data handling obligations between controllers and processors.
Data Processing Agreement Addendum
An Australian-compliant addendum governing data processing responsibilities between controllers and processors under the Privacy Act 1988.
Joint Controller Agreement
An Australian law-governed agreement establishing rights and obligations between joint controllers of personal data under the Privacy Act 1988.
Intra Group Data Sharing Agreement
An Australian law-governed agreement regulating data sharing between entities within the same corporate group, ensuring compliance with privacy laws and data protection requirements.
Dpia Agreement
An Australian agreement governing the conduct of Data Protection Impact Assessments under the Privacy Act 1988 and related privacy laws.
Subprocessor Agreement
An Australian legal agreement governing data processing arrangements between a processor and subprocessor, ensuring compliance with Australian privacy laws and data protection requirements.
Master Data Protection Agreement
An Australian law-governed agreement establishing data protection obligations between parties, ensuring compliance with the Privacy Act 1988 and related privacy legislation.
Controller To Controller Data Processing Agreement
An Australian law-compliant agreement governing personal data sharing between two independent data controllers, ensuring Privacy Act 1988 and APP compliance.
Intra Group Data Transfer Agreement
An Australian law-compliant agreement governing data transfers between entities within the same corporate group, ensuring privacy law compliance and operational efficiency.
Data Management Agreement
An Australian law-governed agreement establishing data management and protection obligations between parties, ensuring compliance with Privacy Act 1988 and related legislation.
Intercompany Data Processing Agreement
An Australian law-governed agreement regulating data processing activities between related companies within the same corporate group.
Controller To Controller DPA
An Australian law-compliant agreement governing personal data sharing between two independent data controllers, ensuring Privacy Act compliance and data protection.
Intercompany Data Sharing Agreement
An Australian-law governed agreement for regulated data sharing between related corporate entities, incorporating privacy law compliance and data protection measures.
DPA Agreement
An Australian-law compliant agreement governing personal information processing between controllers and processors, ensuring adherence to the Privacy Act 1988 and APPs.
Third Party Data Processing Agreement
An Australian-compliant agreement governing the processing of personal information by third-party service providers under Privacy Act 1988 and APPs.
Data Transfer Addendum
An Australian law-compliant addendum governing data transfer arrangements between parties, ensuring compliance with the Privacy Act 1988 and APPs.
Supplier Data Processing Agreement
An Australian-law governed agreement setting out terms for processing personal information between an organization and its supplier, ensuring compliance with Australian privacy laws.
Controller Processor Agreement
An Australian law-compliant agreement governing the processing of personal data between a controller and processor, aligned with the Privacy Act 1988 and APPs.
Order Processing Agreement
An Australian-law governed agreement establishing terms for order processing services, including operational procedures, compliance requirements, and service levels.
Data Protection Agreement For Employees
An Australian-compliant employee data protection agreement establishing rights and obligations for handling personal information in the employment context.
Affiliate Addendum
An Australian law-governed addendum establishing terms and conditions for affiliate marketing relationships, including commercial terms and compliance requirements.
Sub Processing Agreement
An Australian-law governed agreement that establishes terms for sub-processing of personal data, ensuring compliance with privacy laws and data protection requirements.
International Data Transfer Agreement
An Australian law-compliant agreement governing cross-border data transfers, ensuring protection of personal information under the Privacy Act 1988 and APPs.
Data Transfer Agreement
An Australian law-governed agreement establishing terms for secure and compliant data transfer between organizations, ensuring adherence to Australian privacy regulations.
Download our whitepaper on the future of AI in Legal
Genie’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; Genie’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our Trust Centre for more details and real-time security updates.
Read our Privacy Policy.