Privacy Data Processing Agreement Template (Australia)
Updated on 24 August 2026
This Australia data processing agreement is the local equivalent of Jotform's US business associate agreement. Outside the United States, a HIPAA BAA is usually the wrong document; the better match is a controller-processor, customer-vendor or privacy data handling agreement.
Use it when one party processes personal information for another and the services contract needs instructions, security, breach notice, sub-processing, transfer and exit terms.
Tap any highlighted blank in the document below and type straight into it.Free — no sign-up, no watermark
Data Processing Agreement
- Effective date:
- Customer:
- Supplier:
- Role classification:
- Governing law:
1. Processing details
Services involving personal data: . Personal data types: . Data subject categories: .
2. Instructions and permitted use
will process personal data only for the services and documented instructions stated here: . must promptly tell if it believes an instruction conflicts with applicable privacy law.
3. Confidentiality and security
will restrict access to authorised personnel bound by confidentiality and will maintain the following security measures: .
4. Breach and incident notice
will notify without undue delay and no later than hours after becoming aware of a personal data breach or security incident affecting the services, then provide reasonable follow-up information as it becomes available.
5. Sub-processors and transfers
Approved sub-processors: . International transfers: . New sub-processors or materially changed transfer arrangements require the notice, objection or approval process agreed by the parties.
6. Assistance and records
will provide reasonable assistance with individual rights requests, security assessments, audits, regulator enquiries, data protection impact assessments and records needed to demonstrate compliance.
7. Return, deletion and survival
At the end of the services, personal data will be handled as follows: . Confidentiality, security, audit, breach cooperation and deletion evidence duties continue while the supplier retains personal data.
Customer
Date:
Supplier
Date:
The Australia document starts with role classification
Australia does not use a GDPR-style Article 28 processor contract for ordinary private-sector work. The practical equivalent is a privacy and data handling agreement that gives the customer contractual controls over APP compliance, security, use, disclosure, outsourcing and breach escalation.
The template therefore asks whether the supplier is a processor, service provider, contractor, independent controller or joint controller before the obligations are finalised. Do not use a processor contract where both parties decide purposes independently.
Instructions and security must be operational
A strong DPA does more than say comply with privacy law. It states what personal data is processed, whose data it is, why it is processed, where it may go, who may access it and which security measures apply.
The document includes a security schedule so encryption, access control, logging, backup, staff confidentiality, vulnerability management and incident handling can be stated in plain language.
Breach notice should be faster than the legal clock
The processor or service provider should notify the customer quickly enough for the customer to assess notification duties. Waiting until every fact is known can make the controller miss a legal or contractual deadline.
The template uses a short breach-notice field, then allows follow-up reports as facts are confirmed.
Transfers and sub-processors need a real approval path
Cloud hosting, support desks and analytics tools often create hidden sub-processing or international-transfer issues. The template requires a sub-processor approval route, destination list and transfer mechanism rather than a vague outsourcing permission.
If the supplier changes its stack, the customer gets notice and an objection path where local law or the deal requires it.
Why it is better than a copied HIPAA BAA
Jotform source document is healthcare-specific and US-specific. This page keeps the search benefit of the BAA batch but gives non-US users a local privacy agreement that does not invent HIPAA duties where they do not apply.
For Australia, the guidance cites local privacy authority or statute sources and keeps regulated health, public-sector and cross-border transfers flagged for local review.
Australia data processing agreement guide
- Role classification
- Confirms whether the supplier is a processor, service provider, independent controller or joint controller.
- Processing details
- Records subject matter, duration, nature, purpose, data categories and data-subject categories.
- Documented instructions
- Limits processing to the customer instructions and the services contract.
- Confidentiality
- Requires staff and authorised users to be bound by confidentiality.
- Security measures
- Turns security from a generic promise into a schedule of technical and organisational controls.
- Breach notice
- Gives the customer time to assess notification obligations and mitigation steps.
- Sub-processors
- Controls hosting, support, contractors and downstream vendors.
- Individual rights assistance
- Requires help with access, correction, erasure, objection or local equivalent requests.
- Transfers
- Records destinations and transfer mechanism or customer approval.
- Exit
- Requires return, deletion, backup handling and retained-copy justification.
Australia privacy checklist
Review these points before attaching the DPA to the services contract.
Classify the relationship before using the template
Australia does not use a GDPR-style Article 28 processor contract for ordinary private-sector work. The practical equivalent is a privacy and data handling agreement that gives the customer contractual controls over APP compliance, security, use, disclosure, outsourcing and breach escalation.
OAIC Australian Privacy PrinciplesDocument the processing details
The schedule asks for subject matter, duration, nature, purpose, personal-data types, data-subject categories and the controller/customer instructions so the contract is more than a confidentiality addendum.
OAIC Australian Privacy PrinciplesWrite down security measures
Security is not left as a promise to be reasonable. The template asks for access control, encryption or equivalent safeguards, resilience, backup, logging, staff confidentiality and incident response.
Set a breach escalation path
The NDB scheme turns on likely serious harm, so the customer needs prompt vendor notice even when the vendor is not the notifying entity.
OAIC Notifiable Data Breaches schemeControl sub-processors
The processor must not add a sub-processor without the agreed authorisation route and must impose equivalent protection on that sub-processor.
Handle international transfers separately
The transfer schedule asks for destination countries, transfer mechanism and supplementary measures where needed. Do not treat a normal services contract as a transfer assessment.
OAIC Australian Privacy PrinciplesReturn or delete data at exit
The exit clause requires return, deletion or legally required retention to be stated, including backup deletion timing and certificate evidence where appropriate.
How to use this Australia data processing agreement
- Map the processing. List personal data, data subjects, systems, countries and sub-processors.
- Classify roles. Decide whether the supplier acts under instructions or decides purposes independently.
- Write instructions. State the permitted services, purposes and limits on use.
- Add security measures. Use concrete controls rather than a broad compliance promise.
- Set breach notice. Choose a notice period short enough for the customer to assess notification duties.
- Approve sub-processors. List current sub-processors and the process for changes.
- Plan exit. State return, deletion, backup and retained-copy rules before the service ends.
Australia data processing agreement FAQs
Is this a business associate agreement?
No. In Australia, the better equivalent is a data processing or privacy data handling agreement based on local privacy law, not HIPAA.
When do I need a DPA?
Use one when a supplier processes personal information for a customer, especially where the customer sets the purpose and the supplier acts on instructions.
Can a supplier be an independent controller?
Yes. If the supplier decides its own purposes and means, a processor agreement may be the wrong instrument and a data sharing or controller-to-controller arrangement may be needed.
What should the security schedule include?
Access controls, encryption or equivalent safeguards, logging, backup, resilience, staff confidentiality, vulnerability management and incident response.
How quickly should breaches be reported?
The template lets you choose the period. In practice, it should be short enough for the customer to assess legal notification duties and reduce harm.
Are sub-processors allowed?
Only through the approval route in the agreement. Current sub-processors should be listed and changes should trigger notice.
Does this handle international transfers?
It creates a transfer schedule, but parties still need to confirm the correct local transfer mechanism and any risk assessment.
Can this sit inside a services contract?
Yes. It is usually attached to a business contract or SaaS/services agreement and should prevail for privacy terms if there is a conflict.
Related templates
Disclaimer
This Australia template is for general information and document drafting support only. It is not legal advice and does not replace advice from a qualified local professional for regulated transport, privacy, construction, procurement, tax or sector-specific work.


