Contract clause
Data protection clause
A data protection clause sets out how a party that receives personal information under a contract may collect, use, store, disclose and dispose of it. In Australia it ties those duties to the Privacy Act 1988 and the Australian Privacy Principles, and adds the limits and reporting steps the statute leaves to the parties.
Outsourcing a function does not outsource the privacy obligations that come with it. The clause is how a business makes a supplier carry the same standard it is held to, and proves that it asked.
Nuwan Madhusanka · Co-founder
4 min read · Published
Sample clause
a payroll services agreement between Tallowood Payroll and Kinsale Physiotherapy, a fictional clinic group in Toowoomba with 60 staff
9. Personal Information 9.1 In this clause, Personal Information has the meaning in the Privacy Act 1988 (Cth), and Client Data means Personal Information about the Client's employees that Tallowood Payroll receives or creates in providing the Services. 9.2 Tallowood Payroll must comply with the Australian Privacy Principles in handling Client Data, whether or not it would otherwise be bound by them. 9.3 Tallowood Payroll may use Client Data only to provide the Services and must not disclose it to any person other than its personnel who need it and the subcontractors listed in Schedule 4. 9.4 Tallowood Payroll must store Client Data only in Australia unless the Client consents in writing. 9.5 Tallowood Payroll must notify the Client within two business days of becoming aware of any actual or suspected unauthorised access to, disclosure of or loss of Client Data, and must cooperate with any assessment the Client carries out. 9.6 On the Client's written request, Tallowood Payroll must provide a written summary of the steps it takes to protect Client Data.
Sample wording, not legal advice.
Variants
Australian Privacy Principles, supplier below the turnover threshold
The supplier is a small business that the Privacy Act would not otherwise cover, so the contract has to create the obligation.
The Supplier acknowledges that it may not be an APP entity under the Privacy Act 1988 (Cth). For the purposes of this agreement, the Supplier must handle all Personal Information it receives from the Customer as if it were an APP entity bound by the Australian Privacy Principles, including the principles on use and disclosure, cross border disclosure, security and destruction. A breach of those principles in relation to Customer Personal Information is a breach of this agreement.
UK GDPR processor terms
The customer is a controller in the United Kingdom and the supplier processes personal data on its behalf.
The Processor must process Customer Personal Data only on the documented instructions of the Controller, including in relation to transfers outside the United Kingdom. The Processor must ensure that persons authorised to process the data are bound by confidentiality, must implement the measures required by Article 32 of the UK GDPR, must not engage another processor without prior written authorisation, and must delete or return the data at the Controller's choice when the Services end.
United States, California service provider
A business subject to the California Consumer Privacy Act discloses personal information to a vendor for a business purpose.
The Customer discloses Personal Information to the Vendor only for the limited and specified business purposes described in Exhibit B. The Vendor must use, retain and disclose that Personal Information only for those purposes, must comply with its obligations under the California Consumer Privacy Act, must provide the same level of privacy protection the Act requires of the Customer, and must notify the Customer if it determines it can no longer meet those obligations.
What to negotiate
Whose standard applies
Customers covered by the Privacy Act want suppliers bound to the Australian Privacy Principles even where the supplier is exempt as a small business. Suppliers accept that for the customer's data but resist a clause that imports every principle into how they run their own business. Limiting the promise to information received under the contract settles most versions of this argument.
The notification window
A customer that must assess a suspected eligible data breach needs to hear about it early, so it asks for notice within hours. Suppliers prefer a window measured in business days, starting when they become aware rather than when the incident happened. Two business days from awareness, with suspected incidents included, is a common landing point.
Subcontractors and where data sits
A payroll or software supplier rarely works alone, so a flat ban on disclosure is unworkable. The usual answer is a schedule naming current subcontractors and their locations, a notice period before a new one is added, and a right for the customer to object. Offshore storage is often handled in a separate cross border clause.
The risk of leaving it out
Without the clause the customer remains answerable for how its own obligations under the Privacy Act are met, but has no contractual right to limit the supplier's use of the data, to be told promptly about a breach, or to insist the information stays onshore. A small business supplier may owe nothing under the Act at all.
Why a supplier needs its own promise
The Privacy Act 1988 applies to APP entities, which include businesses with an annual turnover above $3 million and some smaller ones, such as those providing a health service. A payroll bureau, a booking platform or a developer may sit below the threshold and owe no statutory duty at all, even while holding a clinic's staff records. The contract fills that gap by requiring the supplier to follow the Australian Privacy Principles for the customer's data. It also turns duties the statute states in general terms, such as taking reasonable steps to protect information, into specific obligations with deadlines that the customer can check and enforce.
How it differs from the other data clauses
This clause is the umbrella. It says what the supplier may do with personal information and names the standard it must meet. The details usually sit in narrower clauses that hang off it: breach notification sets the clock and the contents of a report, cross border transfer controls where the data may go, data return and deletion deals with the end of the contract, and a UK or EU processing clause covers the mandatory Article 28 terms. A short privacy clause pointing to a published policy is a different thing again, written for customers rather than suppliers.
Where it sits in a generated document
A generated services agreement would usually carry the data protection clause after confidentiality, as a numbered clause with its definitions, use limits and notification duty as separate sub clauses. Because documents contain no input fields, the notice period, the storage location and the subcontractor list are written into the text itself. The generator prints no citations, so the reference to the Privacy Act and every period in the draft need checking before it is signed.
Documents that carry this clause
UK data processing agreement template with sub-processorsA data processing agreement is what a UK controller has to have in writing before a processor touches personal data. This one covers a hosted order management platform for a UK retailer, with the processing annex, a table of five named sub-processors and their transfer safeguards, eight security measures, and a breach notice of 48 hours rather than 72.
Privacy policy template written to the Australian Privacy PrinciplesA privacy policy is a list of true statements about what a business does with information, and copying a US template produces a list of false ones. This policy is written for an Australian online store to the thirteen privacy principles, with a table of every service that receives customer data and where it is, which is the part most policies skip.
IT support services agreement with response times by priorityManaged support is sold on a monthly fee and judged on how fast the phone gets answered when nobody can work. This agreement grades every ticket into four priorities with a published response and resolution target, credits the fee when the target is missed, and writes down exactly what the provider hands back on the way out.
Software development agreement with sprints and an acceptance testCustom software goes wrong in the space between delivered and accepted, where one side thinks a sprint is finished and the other is still writing a list. This agreement fixes a ten business day acceptance window against criteria written before the sprint started, and assigns the intellectual property sprint by sprint as each invoice is paid.Questions people ask
Is a data protection clause required by law in Australia?
The Privacy Act 1988 does not prescribe a clause, but an APP entity must take reasonable steps to protect personal information, and handing it to a supplier with no contractual limits makes that hard to demonstrate. For disclosures overseas, APP 8 expects reasonable steps before the information leaves, which in practice means a contract.
Does the clause apply if the supplier is a small business?
The Privacy Act generally does not cover a business with annual turnover of $3 million or less, subject to exceptions. The contract can still bind the supplier to the Australian Privacy Principles for the customer's information, and that promise is enforceable as a term of the agreement even where the statute would not reach the supplier.
What is the difference between personal information and confidential information?
Personal information is information about an identified or reasonably identifiable individual, and statute governs how it is handled. Confidential information is whatever the contract defines as confidential, usually business material. Staff records are both, which is why agreements carry a confidentiality clause and a separate data protection clause rather than relying on one of them.
Should suspected breaches be reported, or only confirmed ones?
Suspected ones. Under the Notifiable Data Breaches scheme, an entity that suspects an eligible data breach must take reasonable steps to assess it within 30 calendar days. A supplier that waits for certainty before telling the customer uses up that time. Most clauses therefore require notice of actual or suspected incidents.
Can the same clause work for UK and Australian customers?
Only partly. A UK customer using a processor needs the specific terms listed in Article 28 of the UK GDPR, such as documented instructions, sub processor authorisation and audit rights. An Australian clause built around the privacy principles will not cover all of them, so cross border agreements usually attach a separate processing schedule.
Who is responsible if the supplier mishandles the data?
Both, in different ways. The customer remains answerable for its own obligations under the Privacy Act, and the supplier is liable to the customer for breaching the clause. The indemnity and liability cap decide how much of the cost actually moves, so those clauses should be read with the data protection clause, not separately.
Put the clause in a finished document
The button opens the document generator with a starting description already filled in. Change it to match your own agreement before you run it.
Create a document with OneCraftRelated clauses
- Privacy clause in a service contractA privacy clause tells a customer what happens to their details and points to the privacy policy. Australian sample for a membership form, with three variants.
- Data breach notification clauseA data breach notification clause sets when a supplier must tell the customer about a breach. Australian sample with 24 and 72 hour steps, and UK and US timing.
- Data processing clause under UK GDPR Article 28A UK data processing clause gives the controller to processor terms UK GDPR Article 28 requires. Sample for a marketing agency, the mandatory points, variants.
- Cross border data transfer clauseA cross border data transfer clause controls whether personal data may leave the country. Australian APP 8 sample, named country and UK and EU variants.
For everything the document generator can do, see the document maker.
Step by step in the builder: Create a document with AI, then Document builder components.
Written and checked by the OneCraft team. Last checked .