Data and privacy clauses in a contract
When one business handles another's customer or staff data, privacy law still holds the original business responsible for what happens to it. These clauses set out who may use the data, how it is protected and what happens when something goes wrong.
10 pages in this collection
The core obligations
The privacy clause commits a party to handle personal information in line with the law that applies to it, which in Australia is usually the Privacy Act and its principles. Data protection turns that into concrete handling rules, and data processing goes further for a supplier that only acts on instructions, limiting what it can do with the data and why. Marketing consent covers the narrower question of using contact details to promote anything, which carries its own rules under spam and privacy law. Start with the privacy clause, then read whichever of the other three matches the relationship.
Security and breaches
Cyber security sets the controls a supplier must keep in place, from access limits to encryption and staff training, and it works best when it names a recognised standard rather than using vague words like reasonable. Data breach notification sets how quickly one party must tell the other about a suspected breach and what the notice must contain. Short deadlines matter here, because the business that owns the relationship with the affected people may have its own legal duty to assess and notify, and it cannot do that without the facts.
Where the data goes and when it ends
Cross border data transfer controls sending information overseas, including to cloud servers, and who stays accountable once it has left. Records retention sets how long information must be kept, which can be driven by tax, employment or industry rules. Data return and deletion covers the end of the contract, when the supplier must hand data back or destroy it and confirm that it has. Audit rights let the customer check that all of this is actually happening. Each page carries sample wording and variants, and none of it is legal advice.
Every page in this collection
- Audit rights clause
Every promise about data handling, pricing or security is only as good as the ability to check it. Audit rights are rarely used, but a supplier that knows they exist behaves differently from one that knows they do not.
- Cross border data transfer clause
Data crosses borders far more often than contracts admit, through offshore support desks, cloud regions and subcontractors in other time zones. The clause makes the supplier say where the data will actually go, so the customer can decide whether that is acceptable.
- Cyber security clause: the controls a supplier must keep
Reasonable security means little until someone writes down what it includes. A good clause names the controls, the standard they are measured against, and how the customer will know they are still in place a year later.
- Data breach notification clause
When an incident happens inside a supplier's systems, the customer cannot start its own legal response until someone tells it. A notification clause is what shortens the gap between the supplier finding out and the customer being able to act.
- Data processing clause under UK GDPR Article 28
Under the UK GDPR a controller may only use a processor that gives sufficient guarantees, and the guarantees have to be in a binding written contract. The clause is short to state and easy to get subtly wrong, because the regulation lists what it must contain.
- Data protection clause
Outsourcing a function does not outsource the privacy obligations that come with it. The clause is how a business makes a supplier carry the same standard it is held to, and proves that it asked.
- Data return and deletion clause
Leaving a software platform is when customers discover whether their records can come with them. The clause is written at the start of the relationship because at the end the supplier has no reason to be quick or generous.
- Marketing consent clause and opt in wording
Under Australia's Spam Act the sender has to prove consent, not the recipient disprove it. The clause and the record of the tick box are the proof, so vague or pre ticked wording leaves a business with nothing to show.
- Privacy clause in a service contract
Most people meet a privacy clause as the paragraph above a signature line or a tick box on a sign up form. Those few sentences carry the notice the Australian Privacy Principles expect at the moment of collection, so they need to be accurate rather than generic.
- Records clause: what to keep and for how long
Disputes about money are usually decided by whoever kept the better paperwork. A records clause makes sure both parties are keeping it, and that the paperwork still exists when an auditor, a regulator or a court asks for it.
Describe the document you need
The document generator writes and lays out the whole thing from one description, then lets you edit every section and download a PDF.
Write a documentStep by step in the builder: write an agreement from a description, then format numbered clauses and callouts. For everything the generator can do, see the document maker.
Related collections
Browse the whole collection: page 1, page 2, page 3, page 4, page 5, page 6, page 7.
Written and checked by the OneCraft team. Last checked .