Skip to main content

Privacy and Data Handling Agreement Template - Australia

This Model Privacy and Data Handling Agreement has been developed for use between entities where one party (the Data Recipient) will receive, access, store, process, or otherwise handle personal or confidential data on behalf of the other party (the Data Discloser). It is suitable for service providers, contractors, SaaS vendors, professional firms, and other data processors handling personal information or confidential datasets in accordance with Australian privacy law and (if applicable) international obligations such as the General Data Protection Regulation (GDPR).

Used 0 time

  • Copy link
  • Report

Effortlessly edit PDFs anywhere

  • Save time and tackle any paperwork task with ease
  • Handle confidential information and signatures securely
  • Send work, negotiate terms and sign everything off with Lumin Sign
Privacy and Data Handling Agreement Template - Australia eSign compatible
Ready for secure eSigning with Lumin Sign
Large thumbnail of Privacy and Data Handling Agreement Template - Australia
1/1
Thumbnail of Privacy and Data Handling Agreement Template - Australia - page 0

Used 0 time

You might also like

Lumin logo
Lumin logo
Lumin logo
Lumin logo
Lumin logo
Lumin logo

Purpose and legal effect of a privacy and data handling agreement

A Privacy and Data Handling Agreement is a legally binding contract that governs how personal, sensitive, and confidential information will be collected, used, stored, transferred, or disclosed by the Data Recipient. It is often used alongside a broader service contract or Master Service Agreement (MSA) to ensure compliance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and applicable data protection obligations.


This template has been designed to:

  • Define the types of data to be shared, the permitted purposes, and applicable data categories (e.g. personal, sensitive, health-related, financial);
  • Set out data handling practices including collection, access control, security, retention, and destruction;
  • Allocate roles and responsibilities of each party as either “Data Controller” or “Data Processor” (or similar);
  • Comply with statutory obligations under the Privacy Act 1988 (Cth) and, where applicable, GDPR and the Notifiable Data Breaches Scheme (Part IIIC of the Privacy Act);
  • Establish audit, breach notification, cross-border transfer, and dispute resolution procedures.

This agreement is essential to mitigate data breach risk, protect individuals’ privacy rights, and ensure enforceable contractual obligations relating to data governance.


Instructions for completion


Customisation and adaptation

This agreement should be tailored to the specific nature of the services being provided, the categories of data involved, and the applicable legal jurisdictions. Particular attention should be paid to:

  • The definition of “Personal Information,” “Confidential Information,” “Data Controller,” and “Data Processor”;
  • Whether data will be transferred, stored, or accessed offshore (including cloud environments);
  • The roles of subcontractors or sub-processors (e.g. SaaS vendors, analytics tools, hosting providers);
  • Duration of data retention, data return, or deletion protocols upon termination of the primary agreement.

Legal and regulatory considerations

This agreement is intended to ensure compliance with the following legal frameworks (as applicable):

  • Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs);
  • General Data Protection Regulation (EU) 2016/679 (GDPR), where personal data of EU residents is handled;
  • Notifiable Data Breaches Scheme — notification of eligible data breaches to the OAIC and affected individuals;
  • Any state-based health privacy or data retention laws (e.g. Health Records Act 2001 (Vic)).

Legal advice should be obtained (e.g. from Maguire Legal at [email protected]) where:

  • The data is sensitive, health-related, or subject to heightened security or ethical obligations;
  • The processing involves cross-border data transfer to jurisdictions without equivalent privacy protections;
  • The agreement will be used in conjunction with complex sub-processing or data-sharing networks.

Supplementary notes

  • Ensure that all referenced documents (e.g. Privacy Policy, Information Security Schedule, Sub-Processor List) are annexed to the agreement.
  • Maintain records of executed agreements for audit and compliance purposes.
  • Conduct regular privacy impact assessments and review agreements periodically (at least annually).
  • Verify that both parties maintain adequate cybersecurity, access controls, and breach response procedures.

Copyright and intellectual property notice

This document and its contents are subject to copyright protection under the Copyright Act 1968 (Cth) and all applicable intellectual property legislation. Unauthorised use, duplication, adaptation, or distribution is strictly prohibited without the prior written consent of Maguire Legal. Citation of excerpts is permitted only where full attribution is provided.


Legal disclaimer

This document has been prepared by Maguire Legal for general guidance purposes only. It does not constitute, and is not intended to constitute, legal advice. No warranties or representations are made as to its legal effect or suitability for specific circumstances. Users must exercise their own judgment and obtain independent legal advice prior to reliance. Maguire Legal disclaims all liability for any loss or damage arising from use of this document in whole or in part.


About Maguire Legal

Maguire Legal is an Australian law firm combining legal advice on all aspects of Australian employment, commercial, corporate and workplace relations law with exceptional business research skills and management development designed to build business capability in Australian enterprises of all types and size.


See Maguire Legal's full collection of essential templates for Australian small businesses.

Discover Lumin's products

Collaborate with existing colleagues and onboard new ones with Lumin and Lumin Sign. Our innovative solutions work great on their own, but they're even better together.

Lumin image

Lumin

An easy-to-use PDF editor that stands alone or integrates with Google Workspace.

Learn more
Lumin Sign image

Lumin Sign

A digital signature workflow tool that seals deals with legally-compliant signatures.

Learn more
Lumin Sign API image

Lumin Sign API

An eSignature API designed to be plugged into your platform with minimal effort.

Learn more