Services/Privacy & Data

Data Processing Agreement.

Sets out who's responsible for personal information once it's handed to a supplier, host or platform partner.

Typical turnaround

3–5 business days

In short

A data processing agreement (DPA) allocates responsibility for handling personal information between a business and a supplier, cloud provider or platform partner that processes data on its behalf. It covers permitted use, sub-processors, cross-border disclosure under Australian Privacy Principle 8, security measures and breach notification obligations aligned with the Notifiable Data Breaches scheme.

Why a general services agreement isn't enough

Where a supplier processes personal information on your behalf — a payroll provider, a CRM host, a marketing platform, an offshore support team — a standard services agreement rarely addresses the specific obligations the Privacy Act 1988 (Cth) expects you to have in place. A data processing agreement makes clear that the supplier is acting on your instructions, restricts it from using the data for its own purposes, and creates the paper trail regulators and customers increasingly expect to see as part of a business's privacy compliance program.

Scope of processing and permitted use

We define precisely what personal information the supplier is permitted to process, for what purposes, and for how long, with an express prohibition on using the data for the supplier's own purposes (such as training models or building its own marketing lists) unless separately and transparently agreed. This scope clause is the anchor for everything else in the agreement — vague or open-ended processing purposes undermine every other protection built around it.

Sub-processors and the chain of accountability

Most suppliers rely on their own sub-processors — cloud hosting, analytics tools, support platforms. We require disclosure of current sub-processors, a right to be notified before new ones are engaged, and a flow-down obligation requiring the supplier to bind its sub-processors to materially equivalent data protection terms. Without this, the chain of accountability breaks the moment data passes to a second-tier vendor the business has never assessed.

Cross-border disclosure and APP 8

Australian Privacy Principle 8 requires a business disclosing personal information to an overseas recipient to take reasonable steps to ensure the recipient doesn't breach the Australian Privacy Principles, and generally makes the disclosing business accountable for the overseas recipient's handling of that information as if it were its own act. Where a supplier or its sub-processors are located offshore — a common reality for cloud infrastructure and SaaS tools — we build in contractual obligations mirroring the APPs, audit or assurance rights, and disclosure to affected individuals in the business's own privacy policy about where their data may be held.

Security measures and audit rights

The DPA should specify baseline security measures the supplier must maintain — encryption, access controls, staff confidentiality obligations — proportionate to the sensitivity of the data involved, along with a right for the business to seek evidence of compliance, such as a current security certification or audit report, rather than relying on bare assurances.

Notifiable data breaches and incident response

Under the Notifiable Data Breaches scheme, an entity that suffers an eligible data breach must notify affected individuals and the OAIC as soon as practicable. Because the business — not the supplier — usually carries this notification obligation, the DPA must require the supplier to notify the business promptly (we typically specify within 24 to 72 hours) of any actual or suspected breach involving the data, and to cooperate with the business's own assessment and notification process rather than leaving it to find out independently.

What the fixed fee covers

  • Data processing agreement (standalone or as a schedule to your existing supplier contract)
  • Scope of processing, permitted use and retention clauses
  • Sub-processor disclosure and flow-down obligations
  • Cross-border disclosure clauses addressing APP 8
  • Security measures and audit/assurance rights
  • Breach notification timeframes aligned to the Notifiable Data Breaches scheme

Mistakes we see

  • Relying on a general services agreement with no specific data processing terms
  • No sub-processor visibility, leaving data flowing to vendors the business has never assessed
  • Assuming offshore hosting is fine without addressing APP 8 accountability obligations
  • Breach notification timeframes left undefined, delaying the business's own OAIC notification obligations
  • No audit or assurance right, relying purely on the supplier's word about its security posture

Who this is for

  • Businesses engaging cloud hosting, SaaS or IT service providers that handle personal information
  • Companies outsourcing payroll, HR, marketing or customer support functions
  • Businesses with offshore suppliers or support teams
  • Organisations building a privacy compliance program ahead of a regulator or customer audit

Frequently asked questions

Do we need a DPA for every supplier we use?
Only where the supplier processes personal information on your behalf — a stationery supplier doesn't need one, but a CRM, payroll or hosting provider does. We assess your supplier list and prioritise where a DPA is genuinely warranted based on the sensitivity and volume of data involved.
Are we still responsible for a breach caused by our supplier?
Generally, yes, at least as far as your own notification obligations and reputational exposure are concerned — the Privacy Act's obligations sit with the entity that collected the information, not just whoever is physically holding it. A DPA doesn't eliminate that responsibility, but it does give you contractual recourse and a faster notification path so you can meet your own obligations.
What if our supplier refuses to sign a DPA?
That's a significant red flag, particularly for suppliers handling sensitive or large volumes of personal information. Where you don't have leverage to negotiate a bespoke DPA, we look for equivalent protections in the supplier's standard terms and assess whether the residual risk is acceptable, or whether an alternative supplier is warranted.
Does a DPA apply if our supplier is based in Australia?
Yes — a DPA is useful regardless of location, since it clarifies scope of processing, security obligations and breach notification even for domestic suppliers. The APP 8 cross-border provisions become relevant specifically where the supplier or its sub-processors are located, or may transfer data, overseas.
Can one DPA cover multiple suppliers, or do we need a separate one for each?
Each supplier relationship needs its own DPA reflecting that supplier's actual data handling, sub-processors and security posture, though we can build a standard template that's quickly adapted across your supplier base once the core terms are settled.

Related

Talk to us

Get a fixed fee for this document

Send us a note about what you're working on. We'll respond within one business day and, if we're a fit, book a free 15-minute consultation with a senior lawyer.

We treat every message as confidential.

CallBook Call