Create a bespoke document in minutes, Â or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Personal Data Transfer Agreement
"I need a Personal Data Transfer Agreement for transferring healthcare patient data from our Toronto-based hospital to a cloud service provider in Vancouver, ensuring compliance with both PIPEDA and provincial health privacy laws, with the transfer to begin in March 2025."
1. Parties: Identification of the data exporter and data importer, including their legal status and contact details
2. Background: Context of the agreement, relationship between parties, and purpose of the data transfer
3. Definitions: Definitions of key terms including Personal Data, Processing, Data Subject, Transfer, Security Measures, and other relevant terms
4. Scope and Purpose of Transfer: Detailed description of the data transfer activities, categories of data, and purposes of processing
5. Obligations of Data Exporter: Responsibilities of the data exporter including data accuracy, legal basis for transfer, and notification requirements
6. Obligations of Data Importer: Commitments of the data importer regarding data processing, security measures, and compliance with Canadian privacy laws
7. Security Measures: Technical and organizational security measures required to protect the transferred data
8. Data Subject Rights: Procedures for handling data subject requests and ensuring their rights are protected
9. Breach Notification: Procedures and timelines for reporting data breaches in accordance with Canadian regulations
10. Audit Rights: Rights of the data exporter to audit the data importer's compliance
11. Term and Termination: Duration of the agreement and conditions for termination
12. Return or Destruction of Data: Requirements for handling personal data upon termination of the agreement
13. Governing Law and Jurisdiction: Specification of Canadian law as governing law and jurisdiction for disputes
1. Sub-Processing: Include when the data importer may engage sub-processors, detailing requirements for approval and obligations
2. Special Categories of Data: Include when sensitive personal information or special categories of data are being transferred
3. Trans-border Data Flows: Include when data will be transferred to multiple jurisdictions beyond the primary recipient
4. Data Protection Impact Assessment: Include when required by Law 25 (Quebec) or when transferring high-risk data
5. Industry-Specific Requirements: Include when transfers involve regulated industries (healthcare, financial services, etc.)
6. Liability and Indemnification: Include when specific liability allocation and indemnification terms are needed beyond standard provisions
7. Insurance Requirements: Include when specific insurance coverage for data protection is required
1. Schedule A - Categories of Personal Data: Detailed list of personal data categories being transferred
2. Schedule B - Purposes of Processing: Comprehensive list of all processing purposes and activities
3. Schedule C - Technical and Organizational Security Measures: Detailed description of security measures implemented by both parties
4. Schedule D - Authorized Sub-processors: List of approved sub-processors and their roles, if applicable
5. Schedule E - Transfer Impact Assessment: Assessment of risks and safeguards for the data transfer
6. Schedule F - Data Subject Rights Procedure: Detailed procedures for handling data subject requests
7. Schedule G - Breach Response Plan: Detailed procedures for responding to and reporting data breaches
Authors
Healthcare
Financial Services
Technology
E-commerce
Telecommunications
Professional Services
Education
Insurance
Retail
Manufacturing
Research and Development
Government Services
Consulting
Legal
Compliance
Information Technology
Information Security
Privacy
Risk Management
Data Governance
Operations
Procurement
Information Management
Corporate Affairs
Regulatory Affairs
Chief Privacy Officer
Data Protection Officer
Privacy Manager
Legal Counsel
Compliance Officer
Information Security Manager
IT Director
Risk Manager
Chief Information Security Officer
Privacy Analyst
Data Protection Manager
Chief Legal Officer
Chief Technology Officer
Information Governance Manager
Contract Manager
Privacy Consultant
Find the exact document you need
DPA Data Processing Agreement
A Canadian-law governed agreement defining rights and obligations between organizations for processing personal data, ensuring compliance with PIPEDA and provincial privacy laws.
Joint Controller Agreement
A Canadian law agreement establishing rights and obligations between organizations that jointly control and process personal information, ensuring compliance with PIPEDA and provincial privacy laws.
Standard Data Processing Agreement
A legally binding agreement governing personal data processing activities in Canada, ensuring compliance with PIPEDA and provincial privacy laws.
Data Processing Addendum DPA
A Canadian Data Processing Addendum that establishes data handling requirements between controllers and processors, ensuring compliance with PIPEDA and provincial privacy laws.
Third Party Processor Agreement
A Canadian-compliant agreement governing the processing of personal information by third-party service providers, ensuring adherence to federal and provincial privacy laws.
Personal Data Collection Agreement
A Canadian-law compliant agreement governing the collection and handling of personal information under PIPEDA and provincial privacy regulations.
Processor To Processor DPA
A Canadian-compliant Data Processing Agreement between two processors handling personal information, ensuring adherence to PIPEDA and provincial privacy laws.
Master Data Protection Agreement
A Canadian-law governed agreement establishing data protection obligations and standards between organizations handling personal information, aligned with PIPEDA and provincial privacy laws.
Data Management Agreement
A Canadian-law governed agreement establishing terms for data management and processing, ensuring compliance with PIPEDA and provincial privacy laws.
Commissioned Data Processing Agreement
A Canadian-law governed agreement establishing terms for outsourced personal information processing, ensuring compliance with PIPEDA and provincial privacy laws.
Third Party Data Processing Agreement
A Canadian-law governed agreement establishing terms for third-party processing of personal information, ensuring compliance with PIPEDA and provincial privacy laws.
Data Transfer Addendum
A Canadian law-governed addendum establishing terms for personal information transfers between parties, ensuring compliance with PIPEDA and provincial privacy laws.
Supplier Data Processing Agreement
A Canadian law-governed agreement establishing terms for personal data processing between a company and its supplier, ensuring compliance with PIPEDA and provincial privacy laws.
Personal Data Transfer Agreement
Canadian-law governed agreement for personal data transfers between organizations, ensuring compliance with PIPEDA and provincial privacy regulations.
Order Processing Agreement
A Canadian-law governed agreement establishing terms and conditions for order processing services between a service provider and client company, ensuring compliance with federal and provincial regulations.
Data Protection Agreement For Employees
A Canadian-compliant agreement governing the protection of employee personal information and data privacy obligations in the employment relationship.
Affiliate Addendum
A Canadian-law governed supplementary agreement establishing terms and conditions for affiliate marketing relationships, including compliance and operational requirements.
Data Privacy Addendum
A Canadian law-compliant addendum establishing data protection obligations between controllers and processors under PIPEDA and provincial privacy regulations.
Sub Processing Agreement
A Canadian-law governed agreement defining terms for delegating data processing activities to a sub-processor, ensuring compliance with federal and provincial privacy laws.
Data Transfer Agreement
A Canadian-law governed agreement that regulates the transfer of data between organizations, ensuring compliance with federal and provincial privacy laws.
Download our whitepaper on the future of AI in Legal
³Ò±ð²Ô¾±±ð’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; ³Ò±ð²Ô¾±±ð’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our for more details and real-time security updates.
Read our Privacy Policy.