Contract clause

Data protection clause

A data protection clause sets out how a party that receives personal information under a contract may collect, use, store, disclose and dispose of it. In Australia it ties those duties to the Privacy Act 1988 and the Australian Privacy Principles, and adds the limits and reporting steps the statute leaves to the parties.

Outsourcing a function does not outsource the privacy obligations that come with it. The clause is how a business makes a supplier carry the same standard it is held to, and proves that it asked.

· Co-founder

4 min read · Published

Sample clause

a payroll services agreement between Tallowood Payroll and Kinsale Physiotherapy, a fictional clinic group in Toowoomba with 60 staff

9. Personal Information 9.1 In this clause, Personal Information has the meaning in the Privacy Act 1988 (Cth), and Client Data means Personal Information about the Client's employees that Tallowood Payroll receives or creates in providing the Services. 9.2 Tallowood Payroll must comply with the Australian Privacy Principles in handling Client Data, whether or not it would otherwise be bound by them. 9.3 Tallowood Payroll may use Client Data only to provide the Services and must not disclose it to any person other than its personnel who need it and the subcontractors listed in Schedule 4. 9.4 Tallowood Payroll must store Client Data only in Australia unless the Client consents in writing. 9.5 Tallowood Payroll must notify the Client within two business days of becoming aware of any actual or suspected unauthorised access to, disclosure of or loss of Client Data, and must cooperate with any assessment the Client carries out. 9.6 On the Client's written request, Tallowood Payroll must provide a written summary of the steps it takes to protect Client Data.

Sample wording, not legal advice.

Variants

Australian Privacy Principles, supplier below the turnover threshold

The supplier is a small business that the Privacy Act would not otherwise cover, so the contract has to create the obligation.

The Supplier acknowledges that it may not be an APP entity under the Privacy Act 1988 (Cth). For the purposes of this agreement, the Supplier must handle all Personal Information it receives from the Customer as if it were an APP entity bound by the Australian Privacy Principles, including the principles on use and disclosure, cross border disclosure, security and destruction. A breach of those principles in relation to Customer Personal Information is a breach of this agreement.

UK GDPR processor terms

The customer is a controller in the United Kingdom and the supplier processes personal data on its behalf.

The Processor must process Customer Personal Data only on the documented instructions of the Controller, including in relation to transfers outside the United Kingdom. The Processor must ensure that persons authorised to process the data are bound by confidentiality, must implement the measures required by Article 32 of the UK GDPR, must not engage another processor without prior written authorisation, and must delete or return the data at the Controller's choice when the Services end.

United States, California service provider

A business subject to the California Consumer Privacy Act discloses personal information to a vendor for a business purpose.

The Customer discloses Personal Information to the Vendor only for the limited and specified business purposes described in Exhibit B. The Vendor must use, retain and disclose that Personal Information only for those purposes, must comply with its obligations under the California Consumer Privacy Act, must provide the same level of privacy protection the Act requires of the Customer, and must notify the Customer if it determines it can no longer meet those obligations.

What to negotiate

The risk of leaving it out

Without the clause the customer remains answerable for how its own obligations under the Privacy Act are met, but has no contractual right to limit the supplier's use of the data, to be told promptly about a breach, or to insist the information stays onshore. A small business supplier may owe nothing under the Act at all.

Why a supplier needs its own promise

The Privacy Act 1988 applies to APP entities, which include businesses with an annual turnover above $3 million and some smaller ones, such as those providing a health service. A payroll bureau, a booking platform or a developer may sit below the threshold and owe no statutory duty at all, even while holding a clinic's staff records. The contract fills that gap by requiring the supplier to follow the Australian Privacy Principles for the customer's data. It also turns duties the statute states in general terms, such as taking reasonable steps to protect information, into specific obligations with deadlines that the customer can check and enforce.

How it differs from the other data clauses

This clause is the umbrella. It says what the supplier may do with personal information and names the standard it must meet. The details usually sit in narrower clauses that hang off it: breach notification sets the clock and the contents of a report, cross border transfer controls where the data may go, data return and deletion deals with the end of the contract, and a UK or EU processing clause covers the mandatory Article 28 terms. A short privacy clause pointing to a published policy is a different thing again, written for customers rather than suppliers.

Where it sits in a generated document

A generated services agreement would usually carry the data protection clause after confidentiality, as a numbered clause with its definitions, use limits and notification duty as separate sub clauses. Because documents contain no input fields, the notice period, the storage location and the subcontractor list are written into the text itself. The generator prints no citations, so the reference to the Privacy Act and every period in the draft need checking before it is signed.

Documents that carry this clause

UK data processing agreement template with sub-processors exampleUK data processing agreement template with sub-processorsA data processing agreement is what a UK controller has to have in writing before a processor touches personal data. This one covers a hosted order management platform for a UK retailer, with the processing annex, a table of five named sub-processors and their transfer safeguards, eight security measures, and a breach notice of 48 hours rather than 72.Privacy policy template written to the Australian Privacy Principles examplePrivacy policy template written to the Australian Privacy PrinciplesA privacy policy is a list of true statements about what a business does with information, and copying a US template produces a list of false ones. This policy is written for an Australian online store to the thirteen privacy principles, with a table of every service that receives customer data and where it is, which is the part most policies skip.IT support services agreement with response times by priority exampleIT support services agreement with response times by priorityManaged support is sold on a monthly fee and judged on how fast the phone gets answered when nobody can work. This agreement grades every ticket into four priorities with a published response and resolution target, credits the fee when the target is missed, and writes down exactly what the provider hands back on the way out.Software development agreement with sprints and an acceptance test exampleSoftware development agreement with sprints and an acceptance testCustom software goes wrong in the space between delivered and accepted, where one side thinks a sprint is finished and the other is still writing a list. This agreement fixes a ten business day acceptance window against criteria written before the sprint started, and assigns the intellectual property sprint by sprint as each invoice is paid.

Questions people ask

Is a data protection clause required by law in Australia?

The Privacy Act 1988 does not prescribe a clause, but an APP entity must take reasonable steps to protect personal information, and handing it to a supplier with no contractual limits makes that hard to demonstrate. For disclosures overseas, APP 8 expects reasonable steps before the information leaves, which in practice means a contract.

Does the clause apply if the supplier is a small business?

The Privacy Act generally does not cover a business with annual turnover of $3 million or less, subject to exceptions. The contract can still bind the supplier to the Australian Privacy Principles for the customer's information, and that promise is enforceable as a term of the agreement even where the statute would not reach the supplier.

What is the difference between personal information and confidential information?

Personal information is information about an identified or reasonably identifiable individual, and statute governs how it is handled. Confidential information is whatever the contract defines as confidential, usually business material. Staff records are both, which is why agreements carry a confidentiality clause and a separate data protection clause rather than relying on one of them.

Should suspected breaches be reported, or only confirmed ones?

Suspected ones. Under the Notifiable Data Breaches scheme, an entity that suspects an eligible data breach must take reasonable steps to assess it within 30 calendar days. A supplier that waits for certainty before telling the customer uses up that time. Most clauses therefore require notice of actual or suspected incidents.

Can the same clause work for UK and Australian customers?

Only partly. A UK customer using a processor needs the specific terms listed in Article 28 of the UK GDPR, such as documented instructions, sub processor authorisation and audit rights. An Australian clause built around the privacy principles will not cover all of them, so cross border agreements usually attach a separate processing schedule.

Who is responsible if the supplier mishandles the data?

Both, in different ways. The customer remains answerable for its own obligations under the Privacy Act, and the supplier is liable to the customer for breaching the clause. The indemnity and liability cap decide how much of the cost actually moves, so those clauses should be read with the data protection clause, not separately.

Put the clause in a finished document

The button opens the document generator with a starting description already filled in. Change it to match your own agreement before you run it.

Create a document with OneCraft

Related clauses

For everything the document generator can do, see the document maker.

Step by step in the builder: Create a document with AI, then Document builder components.

Sources

Written and checked by the OneCraft team. Last checked .