Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Joint Controller Agreement
"I need a Joint Controller Agreement under Canadian law for a partnership between my software company and a marketing analytics firm, where we'll jointly process customer data for targeted advertising campaigns starting March 2025."
1. Parties: Identification of the joint controllers entering into the agreement
2. Background: Context of the joint processing relationship and purpose of the agreement
3. Definitions: Key terms used throughout the agreement, including privacy law-specific terminology
4. Scope and Purpose: Detailed description of the joint processing activities and their purposes
5. Roles and Responsibilities: Allocation of responsibilities between joint controllers for compliance with privacy laws
6. Data Processing Principles: Commitment to privacy principles under PIPEDA and applicable provincial laws
7. Legal Basis for Processing: Identification and documentation of legal grounds for processing personal information
8. Data Subject Rights: Procedures for handling data subject requests and determining controller responsibilities
9. Security Measures: Technical and organizational measures to protect personal information
10. Data Breach Notification: Procedures for handling and reporting privacy breaches
11. Cooperation Obligations: Requirements for controllers to cooperate on compliance matters
12. Liability and Indemnification: Allocation of liability between controllers and indemnification provisions
13. Term and Termination: Duration of the agreement and termination provisions
14. General Provisions: Standard contractual clauses including governing law, notices, and amendments
1. Cross-border Transfers: Required when personal information will be transferred outside of Canada
2. Sector-Specific Requirements: Needed when processing involves regulated sectors like healthcare or financial services
3. Sub-processing: Required when either controller may engage sub-processors
4. Joint Marketing Activities: Needed when controllers collaborate on marketing initiatives
5. Audit Rights: Optional provisions for mutual auditing of privacy compliance
6. Insurance Requirements: Specific insurance obligations for high-risk processing activities
7. Data Protection Impact Assessments: Required for high-risk processing activities
8. Dispute Resolution: Specific procedures for resolving privacy-related disputes
1. Schedule A - Processing Activities: Detailed description of joint processing activities, categories of data, and purposes
2. Schedule B - Technical and Organizational Measures: Specific security measures implemented by each controller
3. Schedule C - Data Subject Request Procedure: Detailed procedures for handling access requests and other data subject rights
4. Schedule D - Breach Response Plan: Detailed procedures for responding to privacy breaches
5. Schedule E - Contact Points: Key contacts for privacy matters, breach notification, and operational issues
6. Schedule F - Sub-processors: List of approved sub-processors and process for adding new ones
7. Appendix 1 - Data Flow Diagrams: Visual representation of data flows between controllers
8. Appendix 2 - Compliance Checklist: Checklist of privacy law requirements and responsible parties
Authors
Applicable Privacy Laws
Business Day
Confidential Information
Consent
Data Breach
Data Protection Impact Assessment
Data Subject
Data Subject Request
Effective Date
Joint Controllers
Joint Processing Activities
Personal Information
PIPEDA
Privacy Commissioner
Processing
Provincial Privacy Laws
Reasonable Purpose
Sensitive Personal Information
Security Measures
Sub-processor
Technical and Organizational Measures
Term
Third Party
Transfer
Working Day
Supervisory Authority
Material Change
Permitted Purpose
Point of Contact
Privacy Impact Assessment
Processing Record
Shared Personal Information
Controller Responsibilities
Compliance Documentation
Cross-border Transfer
Data Protection Requirements
Information Security Incident
Joint Processing Framework
Notice
Scope
Joint Control
Data Protection
Privacy Compliance
Security
Confidentiality
Liability
Indemnification
Cooperation
Breach Notification
Data Subject Rights
Sub-processing
Cross-border Transfer
Audit Rights
Record Keeping
Insurance
Term and Termination
Assignment
Force Majeure
Notices
Severability
Entire Agreement
Amendment
Governing Law
Dispute Resolution
Counterparts
Data Retention
Risk Assessment
Emergency Measures
Regulatory Compliance
Service Levels
Performance Standards
Intellectual Property
Technology
Healthcare
Financial Services
Retail
Education
Marketing and Advertising
Telecommunications
Professional Services
Manufacturing
E-commerce
Insurance
Real Estate
Transportation and Logistics
Media and Entertainment
Legal
Compliance
Information Security
IT
Privacy
Risk Management
Operations
Data Governance
Business Development
Project Management
Commercial
Marketing
Chief Privacy Officer
Data Protection Officer
Legal Counsel
Compliance Manager
Information Security Manager
Risk Manager
Chief Information Officer
Chief Technology Officer
Privacy Analyst
Data Governance Manager
Operations Director
Business Development Manager
Project Manager
IT Director
Chief Commercial Officer
Chief Marketing Officer
Find the exact document you need
DPA Data Processing Agreement
A Canadian-law governed agreement defining rights and obligations between organizations for processing personal data, ensuring compliance with PIPEDA and provincial privacy laws.
Joint Controller Agreement
A Canadian law agreement establishing rights and obligations between organizations that jointly control and process personal information, ensuring compliance with PIPEDA and provincial privacy laws.
Standard Data Processing Agreement
A legally binding agreement governing personal data processing activities in Canada, ensuring compliance with PIPEDA and provincial privacy laws.
Data Processing Addendum DPA
A Canadian Data Processing Addendum that establishes data handling requirements between controllers and processors, ensuring compliance with PIPEDA and provincial privacy laws.
Third Party Processor Agreement
A Canadian-compliant agreement governing the processing of personal information by third-party service providers, ensuring adherence to federal and provincial privacy laws.
Personal Data Collection Agreement
A Canadian-law compliant agreement governing the collection and handling of personal information under PIPEDA and provincial privacy regulations.
Processor To Processor DPA
A Canadian-compliant Data Processing Agreement between two processors handling personal information, ensuring adherence to PIPEDA and provincial privacy laws.
Master Data Protection Agreement
A Canadian-law governed agreement establishing data protection obligations and standards between organizations handling personal information, aligned with PIPEDA and provincial privacy laws.
Data Management Agreement
A Canadian-law governed agreement establishing terms for data management and processing, ensuring compliance with PIPEDA and provincial privacy laws.
Commissioned Data Processing Agreement
A Canadian-law governed agreement establishing terms for outsourced personal information processing, ensuring compliance with PIPEDA and provincial privacy laws.
Third Party Data Processing Agreement
A Canadian-law governed agreement establishing terms for third-party processing of personal information, ensuring compliance with PIPEDA and provincial privacy laws.
Data Transfer Addendum
A Canadian law-governed addendum establishing terms for personal information transfers between parties, ensuring compliance with PIPEDA and provincial privacy laws.
Supplier Data Processing Agreement
A Canadian law-governed agreement establishing terms for personal data processing between a company and its supplier, ensuring compliance with PIPEDA and provincial privacy laws.
Personal Data Transfer Agreement
Canadian-law governed agreement for personal data transfers between organizations, ensuring compliance with PIPEDA and provincial privacy regulations.
Order Processing Agreement
A Canadian-law governed agreement establishing terms and conditions for order processing services between a service provider and client company, ensuring compliance with federal and provincial regulations.
Data Protection Agreement For Employees
A Canadian-compliant agreement governing the protection of employee personal information and data privacy obligations in the employment relationship.
Affiliate Addendum
A Canadian-law governed supplementary agreement establishing terms and conditions for affiliate marketing relationships, including compliance and operational requirements.
Data Privacy Addendum
A Canadian law-compliant addendum establishing data protection obligations between controllers and processors under PIPEDA and provincial privacy regulations.
Sub Processing Agreement
A Canadian-law governed agreement defining terms for delegating data processing activities to a sub-processor, ensuring compliance with federal and provincial privacy laws.
Data Transfer Agreement
A Canadian-law governed agreement that regulates the transfer of data between organizations, ensuring compliance with federal and provincial privacy laws.
Download our whitepaper on the future of AI in Legal
Genie’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; Genie’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our Trust Centre for more details and real-time security updates.
Read our Privacy Policy.