Create a bespoke document in minutes, Â or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Commissioned Data Processing Agreement
"I need a Commissioned Data Processing Agreement for my software company based in Ontario that will be outsourcing cloud storage services to a provider in British Columbia, with specific provisions for handling sensitive customer data and health information starting March 2025."
1. Parties: Identification of the Data Controller and Data Processor, including full legal names and addresses
2. Background: Context of the agreement, relationship between parties, and purpose of the data processing activities
3. Definitions: Definitions of key terms used throughout the agreement, including 'Personal Information', 'Processing', 'Data Subject', 'Security Breach', etc.
4. Scope and Purpose of Processing: Detailed description of the processing activities, types of data involved, and purposes for which data may be processed
5. Obligations of the Data Controller: Responsibilities of the data controller, including providing lawful instructions and ensuring legal basis for processing
6. Obligations of the Data Processor: Core responsibilities of the processor, including processing only on documented instructions, maintaining confidentiality, and implementing security measures
7. Security Measures: Technical and organizational security measures required to protect personal information
8. Sub-processing: Conditions and requirements for engaging sub-processors, including approval process and obligations
9. Data Subject Rights: Procedures for handling data subject requests and processor's assistance obligations
10. Data Breach Notification: Procedures and timeframes for reporting and handling personal data breaches
11. Audit Rights: Controller's rights to audit processor's compliance and processor's obligations to demonstrate compliance
12. Cross-border Transfers: Rules and safeguards for transferring data outside of Canada
13. Term and Termination: Duration of the agreement, termination conditions, and data deletion/return obligations
14. Liability and Indemnification: Allocation of liability and indemnification obligations between parties
15. General Provisions: Standard contractual clauses including governing law, jurisdiction, amendments, and notices
1. Insurance Requirements: Specific insurance obligations for data processing activities, recommended when processing sensitive or high-risk data
2. Business Continuity: Requirements for business continuity and disaster recovery, important for critical processing activities
3. Performance Metrics: Service levels and performance standards, relevant when specific processing performance requirements exist
4. Special Categories of Data: Additional provisions for processing sensitive data categories, required when handling health, biometric, or other sensitive data
5. Data Protection Impact Assessment: Requirements for conducting DPIAs, necessary when processing involves high risk to individuals
6. Fees and Payment: Payment terms and fee structure, needed when processing services are provided for compensation
1. Schedule A - Processing Activities: Detailed description of processing activities, including data categories, purposes, and duration
2. Schedule B - Security Measures: Specific technical and organizational security measures to be implemented
3. Schedule C - Approved Sub-processors: List of pre-approved sub-processors and their processing activities
4. Schedule D - Service Levels: Detailed service level requirements and performance metrics
5. Schedule E - Data Transfer Mechanisms: Specific mechanisms and safeguards for international data transfers
6. Schedule F - Fee Schedule: Detailed breakdown of fees and payment terms for processing services
7. Appendix 1 - Technical Requirements: Technical specifications and requirements for data processing systems
8. Appendix 2 - Contact Details: Key contacts for both parties for various purposes (technical, legal, breach notification)
Authors
Technology and Software
Healthcare
Financial Services
E-commerce
Professional Services
Cloud Computing
Marketing and Advertising
Telecommunications
Education
Insurance
Market Research
Human Resources
Manufacturing
Retail
Logistics and Transportation
Legal
Privacy
Compliance
Information Security
Information Technology
Procurement
Risk Management
Operations
Data Governance
Information Governance
Contract Management
Business Development
Project Management
Chief Privacy Officer
Data Protection Officer
Privacy Manager
Legal Counsel
Compliance Officer
Information Security Manager
IT Director
Chief Information Officer
Chief Technology Officer
Privacy Analyst
Contract Manager
Procurement Manager
Risk Manager
Operations Director
Business Development Manager
Project Manager
Information Governance Manager
Chief Legal Officer
Chief Compliance Officer
Privacy Consultant
Find the exact document you need
DPA Data Processing Agreement
A Canadian-law governed agreement defining rights and obligations between organizations for processing personal data, ensuring compliance with PIPEDA and provincial privacy laws.
Joint Controller Agreement
A Canadian law agreement establishing rights and obligations between organizations that jointly control and process personal information, ensuring compliance with PIPEDA and provincial privacy laws.
Standard Data Processing Agreement
A legally binding agreement governing personal data processing activities in Canada, ensuring compliance with PIPEDA and provincial privacy laws.
Data Processing Addendum DPA
A Canadian Data Processing Addendum that establishes data handling requirements between controllers and processors, ensuring compliance with PIPEDA and provincial privacy laws.
Third Party Processor Agreement
A Canadian-compliant agreement governing the processing of personal information by third-party service providers, ensuring adherence to federal and provincial privacy laws.
Personal Data Collection Agreement
A Canadian-law compliant agreement governing the collection and handling of personal information under PIPEDA and provincial privacy regulations.
Processor To Processor DPA
A Canadian-compliant Data Processing Agreement between two processors handling personal information, ensuring adherence to PIPEDA and provincial privacy laws.
Master Data Protection Agreement
A Canadian-law governed agreement establishing data protection obligations and standards between organizations handling personal information, aligned with PIPEDA and provincial privacy laws.
Data Management Agreement
A Canadian-law governed agreement establishing terms for data management and processing, ensuring compliance with PIPEDA and provincial privacy laws.
Commissioned Data Processing Agreement
A Canadian-law governed agreement establishing terms for outsourced personal information processing, ensuring compliance with PIPEDA and provincial privacy laws.
Third Party Data Processing Agreement
A Canadian-law governed agreement establishing terms for third-party processing of personal information, ensuring compliance with PIPEDA and provincial privacy laws.
Data Transfer Addendum
A Canadian law-governed addendum establishing terms for personal information transfers between parties, ensuring compliance with PIPEDA and provincial privacy laws.
Supplier Data Processing Agreement
A Canadian law-governed agreement establishing terms for personal data processing between a company and its supplier, ensuring compliance with PIPEDA and provincial privacy laws.
Personal Data Transfer Agreement
Canadian-law governed agreement for personal data transfers between organizations, ensuring compliance with PIPEDA and provincial privacy regulations.
Order Processing Agreement
A Canadian-law governed agreement establishing terms and conditions for order processing services between a service provider and client company, ensuring compliance with federal and provincial regulations.
Data Protection Agreement For Employees
A Canadian-compliant agreement governing the protection of employee personal information and data privacy obligations in the employment relationship.
Affiliate Addendum
A Canadian-law governed supplementary agreement establishing terms and conditions for affiliate marketing relationships, including compliance and operational requirements.
Data Privacy Addendum
A Canadian law-compliant addendum establishing data protection obligations between controllers and processors under PIPEDA and provincial privacy regulations.
Sub Processing Agreement
A Canadian-law governed agreement defining terms for delegating data processing activities to a sub-processor, ensuring compliance with federal and provincial privacy laws.
Data Transfer Agreement
A Canadian-law governed agreement that regulates the transfer of data between organizations, ensuring compliance with federal and provincial privacy laws.
Download our whitepaper on the future of AI in Legal
³Ò±ð²Ô¾±±ð’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; ³Ò±ð²Ô¾±±ð’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our for more details and real-time security updates.
Read our Privacy Policy.