Create a bespoke document in minutes, Â or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Data Protection Addendum
"I need a Data Protection Addendum under New Zealand law for my software company that will be engaging a local cloud storage provider from March 2025, with standard security measures and breach notification procedures included."
1. Parties: Identification of the data controller/business and data processor/service provider, including their registered addresses and company details
2. Background: Context of the DPA, reference to the main agreement, and purpose of this addendum
3. Definitions: Key terms including Personal Information, Processing, Data Breach, Controller, Processor, Sub-processor, and other relevant terms under NZ Privacy Act
4. Scope and Purpose of Processing: Details of what personal information will be processed and for what purposes
5. Roles and Responsibilities: Clear delineation of roles as controller/processor and respective obligations
6. Compliance with Privacy Laws: Commitment to comply with NZ Privacy Act 2020 and other applicable data protection laws
7. Data Security Measures: Technical and organizational measures required to protect personal information
8. Data Breach Notification: Procedures for handling and reporting privacy breaches, including mandatory notification requirements
9. Sub-processing: Rules and requirements for engaging sub-processors
10. Cross-border Data Transfers: Requirements and safeguards for transferring data outside New Zealand
11. Data Subject Rights: Procedures for handling data subject requests and rights under privacy laws
12. Term and Termination: Duration of the DPA and specific termination provisions related to data protection
13. Return or Destruction of Data: Obligations regarding personal information upon termination of services
1. GDPR Compliance: Additional provisions for compliance with GDPR when dealing with EU data subjects
2. Data Protection Impact Assessments: Procedures for conducting DPIAs when required for high-risk processing
3. Specific Industry Requirements: Additional requirements for specific industries (e.g., healthcare, financial services)
4. Insurance Requirements: Specific insurance obligations related to data protection and cyber security
5. Audit Rights: Detailed audit procedures and requirements beyond basic compliance verification
6. Data Localization Requirements: Specific requirements for data storage locations and restrictions
7. Business Continuity and Disaster Recovery: Specific provisions for ensuring data availability and recovery
1. Schedule 1 - Details of Processing: Detailed description of processing activities, categories of data subjects, types of personal information, and processing purposes
2. Schedule 2 - Technical and Organizational Security Measures: Detailed security requirements and standards to be maintained
3. Schedule 3 - Approved Sub-processors: List of approved sub-processors and their processing activities
4. Schedule 4 - Cross-border Transfer Mechanisms: Details of mechanisms used for international data transfers
5. Schedule 5 - Data Breach Response Plan: Detailed procedures and contact information for breach response
6. Appendix A - Contact Details: Key contacts for privacy-related communications and breach notification
7. Appendix B - Compliance Checklist: Checklist of privacy principles and compliance requirements under NZ Privacy Act 2020
Authors
Technology
Healthcare
Financial Services
Education
E-commerce
Professional Services
Telecommunications
Insurance
Real Estate
Government and Public Sector
Retail
Manufacturing
Cloud Services
Consulting
Marketing and Advertising
Legal
Compliance
Information Security
Information Technology
Risk Management
Procurement
Vendor Management
Operations
Data Governance
Privacy
Information Management
Contract Management
Privacy Officer
Data Protection Officer
Chief Information Security Officer
Legal Counsel
Compliance Manager
Risk Manager
Information Technology Manager
Chief Technology Officer
Chief Legal Officer
Procurement Manager
Vendor Management Officer
Information Security Manager
Operations Manager
Chief Information Officer
Contract Manager
Privacy Manager
Data Governance Manager
Find the exact document you need
Intra Group Data Processing Agreement
A New Zealand law-governed agreement regulating intra-group personal data processing activities and ensuring Privacy Act 2020 compliance within corporate groups.
Pre Negotiation Agreement
A New Zealand law-governed agreement establishing terms for preliminary business negotiations, including confidentiality and non-binding provisions.
Product Development Non Disclosure Agreement
A New Zealand-law governed agreement protecting confidential information shared during product development activities.
Joint Controller Agreement
A New Zealand law-governed agreement establishing responsibilities and obligations between organizations that jointly control and process personal data under the Privacy Act 2020.
Data Processing Addendum
A New Zealand-compliant legal agreement governing the processing of personal information between a data controller and data processor under the Privacy Act 2020.
Data Agreement
A New Zealand-compliant agreement governing the terms and conditions for data handling between parties, ensuring alignment with local privacy laws and regulations.
Subprocessor Agreement
A New Zealand law-governed agreement that regulates the relationship between a data processor and subprocessor for handling personal data processing activities.
DPA Contract
A New Zealand-compliant Data Processing Agreement governing personal data handling between controllers and processors under NZ Privacy Act 2020.
Controller To Controller Data Processing Agreement
A New Zealand-compliant agreement governing personal data sharing between two independent data controllers, ensuring adherence to the Privacy Act 2020.
DPA Agreement
A New Zealand-compliant agreement governing the processing of personal data between a controller and processor, ensuring adherence to the Privacy Act 2020.
Data Transfer Addendum
A New Zealand law-compliant addendum governing cross-border personal data transfers under the Privacy Act 2020, establishing security measures and compliance requirements.
International Data Transfer Agreement
A New Zealand law-governed agreement establishing requirements and safeguards for international transfer of personal and business data, ensuring compliance with NZ Privacy Act 2020.
Data Protection Addendum
A legal document under New Zealand law that establishes data protection obligations and privacy compliance requirements between parties processing personal information.
Download our whitepaper on the future of AI in Legal
³Ò±ð²Ô¾±±ð’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; ³Ò±ð²Ô¾±±ð’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our for more details and real-time security updates.
Read our Privacy Policy.