Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Data Transfer Agreement
"I need a Data Transfer Agreement to cover the transfer of customer data from our UK office to our new subsidiary in Singapore, ensuring compliance with UK GDPR and including provisions for AI-driven data processing starting from March 2025."
1. Parties: Identification of data exporter and data importer, including full legal names and registered addresses
2. Background: Context of the data transfer relationship and purpose of the agreement
3. Definitions: Key terms used throughout the agreement, including specific data protection terminology
4. Scope and Purpose of Transfer: Details of what data is being transferred and for what specific purposes
5. Obligations of the Parties: Specific responsibilities of both data exporter and importer
6. Data Security Measures: Technical and organizational measures for data protection
7. Data Subject Rights: How data subject requests will be handled
8. Breach Notification: Procedures for handling and reporting data breaches
9. Term and Termination: Duration of agreement and termination provisions
1. Sub-processing: Rules for engaging sub-processors - include when the data importer may need to engage other parties to process the data
2. Audit Rights: Rights to audit data processing activities - include when regular compliance verification is required
3. Data Return/Destruction: Procedures for returning or destroying data - include when specific data lifecycle management is required
4. Insurance: Insurance requirements for data processing activities - include when dealing with high-risk or sensitive data
1. Schedule 1 - Description of Transfer: Detailed description of the data transfer including categories of data subjects and data
2. Schedule 2 - Technical and Organizational Measures: Detailed security measures implemented by the parties
3. Schedule 3 - Standard Contractual Clauses: If applicable, the relevant SCCs for international transfers
4. Schedule 4 - Approved Sub-processors: List of approved sub-processors, if applicable
5. Schedule 5 - Transfer Impact Assessment: Assessment of risks and safeguards for international transfers
Authors
Processing
Data Subject
Data Controller
Data Processor
Data Exporter
Data Importer
Special Categories of Personal Data
Sub-processor
Technical and Organisational Measures
Supervisory Authority
Data Protection Laws
UK GDPR
EU GDPR
Data Protection Act 2018
Standard Contractual Clauses
Personal Data Breach
Transfer
Permitted Purpose
Appropriate Safeguards
Third Country
EEA
Restricted Transfer
Transfer Impact Assessment
Security Breach
Business Day
Confidential Information
Group Company
Representatives
Services
Data Security
Confidentiality
Transfer Mechanisms
Technical and Organizational Measures
Audit Rights
Compliance
Breach Notification
Data Subject Rights
Sub-processing
Cross-border Transfers
Liability
Indemnification
Term and Termination
Governing Law
Dispute Resolution
Force Majeure
Assignment
Severability
Entire Agreement
Amendment
Notice Requirements
Data Return/Destruction
Warranties and Representations
Insurance
Service Levels
Record Keeping
Cooperation
Find the exact document you need
Dpa Addendum
A UK-law compliant addendum defining data processing obligations between controllers and processors under GDPR and DPA 2018.
Joint Data Controller Agreement
A legally binding agreement under English and Welsh law that establishes responsibilities between organizations jointly controlling personal data processing.
Third Party Processor Agreement
A legally binding agreement under English and Welsh law governing the processing of personal data by a third party on behalf of a data controller.
Personal Data Collection Agreement
A legally binding agreement under English and Welsh law governing the collection and processing of personal data in compliance with UK GDPR and related legislation.
International Data Protection Agreement
A legally binding agreement under English and Welsh law governing international personal data processing and transfer arrangements between controllers and processors.
Data Sharing Agreement Controller To Processor
A legally binding agreement under English and Welsh law establishing terms for data processing between a controller and processor, ensuring UK GDPR compliance.
Processor To Processor Dpa
A legal agreement under English and Welsh law governing data processing arrangements between two processors, ensuring UK GDPR compliance.
Master Data Protection Agreement
A legal agreement under English and Welsh law governing the processing of personal data between organizations, ensuring compliance with UK data protection regulations.
Intra Group Data Transfer Agreement
A UK law-governed agreement regulating personal data transfers between entities within the same corporate group, ensuring compliance with UK data protection regulations.
Data Management Agreement
A legal agreement under English and Welsh law governing the terms of data handling and processing between parties, ensuring compliance with UK data protection regulations.
Data Controller To Data Controller Agreement
An English law agreement governing personal data sharing between two independent data controllers, ensuring UK GDPR compliance.
Commissioned Data Processing Agreement
A legal agreement under English and Welsh law governing the processing of personal data between a controller and processor, ensuring UK GDPR compliance.
Controller To Controller Dpa
A legal agreement under English and Welsh law governing personal data sharing between two independent data controllers, ensuring UK GDPR compliance.
Dpa Agreement
A legally binding agreement under English and Welsh law that governs the processing of personal data between a controller and processor, ensuring UK GDPR compliance.
Third Party Data Processing Agreement
An English law agreement governing the processing of personal data between a controller and processor under UK GDPR requirements.
Data Transfer Addendum
A legal document under English and Welsh law that governs the transfer of personal data between organizations in compliance with UK data protection regulations.
Supplier Data Processing Agreement
A legal agreement under English and Welsh law governing personal data processing arrangements between controllers and processors, ensuring UK GDPR compliance.
Personal Data Transfer Agreement
An England and Wales law-governed agreement establishing terms for compliant transfer of personal data between organizations under UK data protection regulations.
Controller Processor Agreement
A legal agreement under English and Welsh law governing the relationship between data controllers and processors, ensuring compliance with UK data protection requirements.
Order Processing Agreement
A legal agreement under English and Welsh law governing the processing of orders and associated data, ensuring compliance with UK data protection regulations.
Data Protection Agreement For Employees
A legally binding agreement under English and Welsh law governing the processing and protection of employee personal data in compliance with UK data protection legislation.
Affiliate Addendum
A supplementary legal document under English and Welsh law that modifies existing affiliate agreements, outlining additional terms and conditions for affiliate marketing relationships.
Sub Processing Agreement
An English law agreement governing the relationship between a processor and sub-processor for personal data processing activities.
Data Protection Addendum
A legal document under English and Welsh law that establishes data protection obligations between parties processing personal data in compliance with UK GDPR.
Data Transfer Agreement
A legal agreement under English and Welsh law governing the transfer of personal data between organizations, ensuring compliance with UK data protection regulations.
Download our whitepaper on the future of AI in Legal
Genie’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; Genie’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our Trust Centre for more details and real-time security updates.
Read our Privacy Policy.