Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Data Protection Addendum
I need a Data Protection Addendum that outlines the responsibilities and obligations of both parties in relation to the processing of personal data, ensuring compliance with the GDPR. It should include details on data processing activities, security measures, data breach protocols, and rights of data subjects.
What is a Data Protection Addendum?
A Data Protection Addendum is a legal agreement that sets out how companies handle and protect personal data when working together. It builds on your main contract to meet Danish and EU data protection requirements, especially those under GDPR. Think of it as your rulebook for keeping customer and employee information safe when sharing it with business partners.
In Denmark, these addendums spell out key responsibilities like data security measures, breach reporting steps, and rules for international data transfers. They're particularly important for Danish companies working with vendors, cloud services, or any partners who process personal data on their behalf. The Danish Data Protection Agency (Datatilsynet) expects organizations to have these agreements in place before sharing any personal information.
When should you use a Data Protection Addendum?
Use a Data Protection Addendum anytime your Danish company shares personal data with external partners or service providers. This includes common situations like hiring cloud storage providers, working with HR software companies, or partnering with marketing agencies that handle customer information. The Danish Data Protection Act and GDPR require these agreements before any data sharing begins.
The timing is crucial - put this agreement in place before sending any personal data to your business partner. For example, when signing up with a new payroll service, launching an online shop platform, or engaging IT consultants who might access employee records. Getting this document right from the start helps avoid fines from Datatilsynet and protects both parties if something goes wrong.
What are the different types of Data Protection Addendum?
- Basic Controller-Processor Agreement: The standard version used when one Danish company processes data on behalf of another, covering GDPR essentials like security measures and data handling procedures
- Multi-Party Data Processing Agreement: Used for complex projects involving multiple data processors or sub-processors, common in IT and healthcare sectors
- International Transfer DPA: Enhanced version with extra safeguards for data leaving Denmark/EU, including Standard Contractual Clauses
- Industry-Specific DPA: Tailored versions for sectors like healthcare or finance, with additional provisions for sensitive data handling under Danish law
- Light DPA: Simplified version for small businesses or low-risk processing, still maintaining GDPR compliance
Who should typically use a Data Protection Addendum?
- Data Controllers: Danish companies that collect personal data and need to share it, like retailers with customer databases or employers with staff records
- Data Processors: Service providers who handle data on behalf of controllers, such as cloud storage companies, payroll services, or marketing agencies
- Legal Teams: In-house lawyers or external counsel who draft and review these agreements to ensure GDPR compliance
- DPOs: Data Protection Officers who oversee data handling practices and advise on compliance requirements
- IT Security Teams: Technical staff who implement the security measures specified in the addendum
- Datatilsynet: The Danish Data Protection Agency, which enforces these agreements and investigates compliance
How do you write a Data Protection Addendum?
- Data Mapping: List all personal data types being shared, including special categories under GDPR
- Processing Details: Document how, why, and where the data will be processed, stored, and accessed
- Security Measures: Outline specific technical and organizational safeguards that will protect the data
- Contact Information: Gather details for key representatives, including DPOs from both parties
- Sub-processor List: Identify any third parties who might handle the data
- Transfer Mechanisms: Determine if data leaves Denmark/EU and which legal transfer tools apply
- Template Selection: Use our platform to generate a customized, GDPR-compliant agreement that includes all required elements
What should be included in a Data Protection Addendum?
- Scope Definition: Clear description of data types, processing purposes, and duration under Danish law
- Party Roles: Explicit designation of controller and processor roles per GDPR Article 28
- Security Measures: Specific technical and organizational safeguards meeting Danish standards
- Breach Protocol: Notification procedures and response timelines aligned with Datatilsynet requirements
- Sub-processor Rules: Terms for appointing and managing additional data processors
- Transfer Mechanisms: Legal basis for international data transfers outside Denmark/EU
- Audit Rights: Controller's inspection and verification powers
- Termination Terms: Data deletion or return procedures when processing ends
What's the difference between a Data Protection Addendum and a Data Protection Agreement?
A Data Protection Addendum differs significantly from a Data Protection Agreement in several key ways, though they're often confused in Danish business settings. While both deal with personal data protection, their structure and application serve different purposes under Danish law.
- Document Structure: A Data Protection Addendum supplements an existing contract, adding GDPR-specific terms to an already established business relationship. A Data Protection Agreement stands alone as a complete agreement.
- Timing and Implementation: Addendums are typically added to contracts after the main agreement is in place, especially when data processing wasn't initially contemplated. Agreements are negotiated and signed as primary documents from the start.
- Scope and Flexibility: Addendums are more focused and limited to data protection matters, while Agreements can cover broader data governance issues and operational details.
- Legal Integration: Addendums must work within the terms of the main contract, while Agreements set their own independent terms and conditions.
Download our whitepaper on the future of AI in Legal
ұԾ’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; ұԾ’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our for more details and real-time security updates.
Read our Privacy Policy.