蜜桃传媒

Controller To Controller Agreement Template for Germany

A comprehensive legal agreement governed by German law that establishes the framework for two or more independent data controllers to jointly process personal data in compliance with the GDPR and German Federal Data Protection Act (BDSG). This agreement defines the respective roles, responsibilities, and obligations of each controller, including their duties towards data subjects, security measures, and breach notification procedures. It ensures transparency in data processing activities and establishes clear accountability mechanisms as required under Article 26 of the GDPR and relevant German data protection regulations.

Typically:
i
This cost is based on prices provided by
6 legal services in your market.
With 蜜桃传媒AI:

拢0

i
Generate and export your first
document completely free.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Get template free

Your data doesn't train 蜜桃传媒's AI

You keep IP ownership聽of your docs

4.6 / 5
4.6 / 5
4.8 / 5
Alternatively...

What is a Controller To Controller Agreement?

The Controller to Controller Agreement is essential when two or more organizations jointly determine the purposes and means of processing personal data in Germany. This document is particularly crucial for businesses engaged in collaborative projects, shared services, or joint ventures where personal data processing is involved. It must comply with both the GDPR and the German Federal Data Protection Act (BDSG), addressing specific German regulatory requirements and enforcement practices. The agreement outlines each party's obligations regarding data subject rights, transparency requirements, and security measures, while establishing clear lines of responsibility and liability allocation. It's particularly important in the German context due to the strict regulatory environment and the active role of German data protection authorities in enforcement.

What sections should be included in a Controller To Controller Agreement?

1. Parties: Identification of the contracting parties including registered addresses and company details

2. Background: Context of the agreement and brief description of data processing activities

3. Definitions: Key terms used in the agreement, including GDPR-specific terminology

4. Scope and Purpose: Detailed description of joint processing activities and purposes

5. Roles and Responsibilities: Specific obligations of each controller and allocation of responsibilities

6. Data Protection Principles: Commitment to GDPR principles and lawful bases for processing

7. Transparency Obligations: Requirements for informing data subjects about joint processing

8. Data Subject Rights: Procedures for handling data subject requests and designated contact points

9. Security Measures: Technical and organizational measures for data protection

10. Personal Data Breaches: Procedures for breach notification and cooperation

11. Liability and Indemnification: Distribution of liability between controllers and indemnification provisions

12. Term and Termination: Duration of agreement and termination conditions

13. Governing Law and Jurisdiction: Confirmation of German law application and jurisdiction

14. General Provisions: Standard contractual clauses including severability and entire agreement

What sections are optional to include in a Controller To Controller Agreement?

1. International Transfers: Required when personal data will be transferred outside the EEA

2. Supervisory Authority Communication: Include when specific arrangements for DPA communications are needed

3. Sub-processing: Include when either controller may engage sub-processors

4. Insurance Requirements: Include when specific insurance coverage needs to be maintained

5. Audit Rights: Include when parties want specific audit provisions beyond statutory requirements

6. Cost Allocation: Include when there are specific cost-sharing arrangements for joint activities

What schedules should be included in a Controller To Controller Agreement?

1. Schedule 1 - Processing Activities: Detailed description of data processing activities, categories of data and data subjects

2. Schedule 2 - Technical and Organizational Measures: Detailed security measures implemented by both parties

3. Schedule 3 - Contact Details: Key contacts for operational matters, data protection officers, and data subject requests

4. Schedule 4 - Standard Information Provision: Template for information to be provided to data subjects

5. Appendix A - Data Flow Diagram: Visual representation of data flows between controllers

6. Appendix B - Incident Response Plan: Detailed procedures for handling data breaches

Authors

Alex Denne

Advisor @ 蜜桃传媒AI | 3 x UCL-Certified in Contract Law & Drafting | 4+ Years Managing 1M+ Legal Documents

Jurisdiction

Germany

Cost

Free to use

Find the document you need

Data Processing Contract

A German law-governed agreement establishing terms for GDPR-compliant personal data processing between controller and processor.

Download

Controller To Controller Agreement

A German law-governed agreement establishing joint processing arrangements between two or more data controllers under GDPR and BDSG requirements.

Download

Joint Controller Agreement

A German law-governed agreement establishing shared data protection responsibilities between joint controllers under GDPR Article 26 and BDSG requirements.

Download

Standard Data Processing Agreement

A German law-governed Data Processing Agreement ensuring GDPR compliance for personal data processing between controller and processor.

Download

Data Processing Addendum

A German law-compliant Data Processing Addendum that establishes terms for personal data processing under GDPR and BDSG requirements.

Download

Intra Group Data Transfer Agreement

German law-governed agreement regulating personal data transfers between group companies, ensuring GDPR and BDSG compliance.

Download

Intercompany Data Processing Agreement

German law-governed data processing agreement between group companies, compliant with GDPR and BDSG requirements.

Download

Data Transfer Addendum

German law-governed Data Transfer Addendum ensuring GDPR compliance and German BDSG requirements for secure personal data transfers between organizations.

Download

Personal Data Transfer Agreement

A German law-governed agreement for compliant transfer of personal data between parties, ensuring GDPR and BDSG compliance.

Download
See more related templates

骋别苍颈别鈥檚 Security Promise

蜜桃传媒 is the safest place to draft. Here鈥檚 how we prioritise your privacy and security.

Your data is private:

We do not train on your data; 骋别苍颈别鈥檚 AI improves independently

All data stored on 蜜桃传媒 is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it