Data sharing agreement between two controllers
A data sharing agreement between two controllers, drafted for the business with the privacy notice, for a fixed fee of £795 in five working days.
Data sharing agreement between two controllers
A data sharing agreement for two businesses that each decide what they do with the data, drafted for the business, covering controller to controller and why Article 28 does not apply, independent controllers, joint controllers and the arrangement the law requires, the purposes, the lawful basis each party needs and the transparency, security, breaches and the cooperation between two controllers, retention, onward sharing and the data the recipient may keep, and the code of practice and the assessment behind the agreement. £795 with the privacy notice, delivered in five working days.
Buy now, £795When two businesses share personal data and each decides what it does with it (a referral partner, a joint venture, a supplier using the data for its own purposes), neither is the other's processor and a data processing agreement is the wrong document; what the law expects is a data sharing agreement that records why the data is shared, the lawful basis each party relies on, what each tells the individuals, how each secures the data, what happens on a breach and what the recipient may do with the data afterwards. I draft the data sharing agreement and the privacy notice for the business for a fixed fee of £795, delivered in five working days, with a note on the operational steps the documents assume.
Who this is for
Businesses in England and Wales sharing personal data with a partner, a group company, a supplier acting for its own purposes or a joint venture, and businesses who have been sent a processing agreement for a relationship that is not one.
What matters in a data sharing agreement
Controller to controller and why Article 28 does not apply
Article 28 of the UK GDPR requires a written contract between a controller and its processor containing the terms the Article lists, but a recipient that decides its own purposes for the data (a partner that markets to the referred customers, an insurer that assesses the risk, a group company that runs its own operations) is a controller in its own right and not a processor, so that a DPA imposed on it misdescribes the relationship and leaves the real questions (what each may do, on what basis, who tells the individuals) unanswered; the agreement should say that each party is a controller of the data it receives, which is the starting point the Information Commissioner's data sharing code of practice under section 121 of the Data Protection Act 2018 takes.
Independent controllers, joint controllers and the arrangement the law requires
Two controllers may be independent (each decides its own purposes and means, sharing data between them) or joint under Article 26 of the UK GDPR (they jointly determine the purposes and means of a shared processing, such as a jointly run database or campaign), and the agreement should say which, because joint controllers must have an arrangement setting out their respective responsibilities (who gives the notice, who answers requests, who is the contact point) and must make the essence of it available to the individuals, while independent controllers each carry their own obligations in full; the agreement for joint controllers contains the arrangement, and the agreement for independent controllers records that each is responsible for its own compliance.
The purposes, the lawful basis each party needs and the transparency
The agreement should state the purposes for which the data is shared and the purposes for which the recipient may use it (no more), the lawful basis each party relies on for its own processing (the discloser for the disclosure, the recipient for its use: contract, legitimate interests with the interest stated and the balance recorded, consent where the individuals have given it for the sharing, legal obligation where a law requires it), the condition under Article 9 and Schedule 1 to the Data Protection Act 2018 where special category data is shared, and the transparency: the discloser tells the individuals in its privacy notice that the data is shared and with whom, and the recipient gives its own notice under Article 14 within a month or at first contact, with the agreement allocating who says what and when.
Security, breaches and the cooperation between two controllers
Each controller must secure the data it holds under Article 32 of the UK GDPR, and the agreement should state the security the parties expect of each other in transit and at rest, the method of transfer (encrypted, through a stated channel, not by email attachment), the persons who may access the data, and the cooperation on breaches: each party notifies the other of a breach affecting the shared data within a stated period so that each can meet its own seventy-two-hour deadline under Article 33, each is responsible for its own notification to the regulator and to the individuals, and the parties coordinate so that the individuals receive one coherent message; the agreement should also provide for cooperation on subject access requests.
Retention, onward sharing and the data the recipient may keep
The agreement should state how long the recipient may keep the shared data (for the purpose, and no longer, with deletion or return at the end of the relationship), whether the recipient may share it onward (usually not without the discloser's agreement and the individuals' notice), what the recipient may do when the relationship ends (keep what it has a basis for as its own controller, delete the rest), and the position on the data the recipient has combined with its own; a data sharing agreement that leaves the recipient free to keep and use the data for ever has shared the data without limit, which the discloser's privacy notice almost certainly did not say.
The code of practice and the assessment behind the agreement
The Information Commissioner's data sharing code of practice expects a controller sharing data to have considered whether the sharing is necessary and proportionate, to have assessed the risks (a data protection impact assessment under Article 35 of the UK GDPR where the sharing is likely to result in a high risk, which large-scale or special category sharing usually is), to have a written agreement, to have told the individuals, and to review the arrangement; the note that comes with the documents sets out the assessment the business should record, because the agreement is the evidence that the sharing was thought about; data protection liability sits with each party for its own failures under Article 82, and the agreement can add an indemnity for a party's breach of the agreement's terms.
What it costs
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Review of a customer's DPA, £495. They sent theirs and you need to know what you are accepting. Returned marked up with the changes to ask for and an explanation. Three working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Our partner sent us a data processing agreement. Are we their processor?
Only if you process the data on their instructions for their purposes. If you decide what you do with it (marketing to the customers, assessing them, running your own service), you are a controller and the right document is a data sharing agreement, which the business can offer instead.
Who tells the individuals that their data has been shared?
Both, usually: the discloser in its privacy notice (that it shares with whom and why), and the recipient under Article 14 within a month or at first contact. The agreement allocates who says what and when.
Can the recipient keep the data after the partnership ends?
Only what it has its own basis to keep as a controller, with the rest deleted or returned. An agreement silent on retention has shared the data without limit, and the discloser's notice did not say that.
Related guidance and services
- Data protection agreements and privacy terms, £795, the service this page describes
- SaaS and technology contracts, £995
- Terms and conditions drafting, £995
- Data sharing agreement for a referral partnership
- Data processing agreement for a recruitment agency
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.