Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Data Protection Addendum
"I need a data protection addendum ensuring compliance with GDPR, covering data processing activities for a 3-year contract, including breach notification within 72 hours and annual audits of data handling practices."
What is a Data Protection Addendum?
A Data Protection Addendum spells out how companies will handle and protect personal data when working together. It's a crucial supplement to main contracts, especially under the Philippines' Data Privacy Act of 2012, which requires strict safeguards for personal information processing.
This agreement details specific security measures, data breach procedures, and each party's responsibilities for protecting sensitive information. Companies in the Philippines use these addendums to ensure compliance with privacy laws while sharing customer data, employee records, or other personal information with vendors, partners, or service providers.
When should you use a Data Protection Addendum?
Use a Data Protection Addendum anytime your business shares personal data with outside parties in the Philippines. This includes hiring cloud service providers, outsourcing HR functions, working with marketing agencies, or partnering with companies that need access to your customer database.
Many Philippine companies add these addendums when signing contracts with international vendors, updating existing service agreements, or expanding operations that involve data processing. It's particularly important when dealing with sensitive information like financial records, health data, or employee details that fall under the Data Privacy Act's strict requirements.
What are the different types of Data Protection Addendum?
- Basic Data Protection Addendum: Covers essential data handling requirements under Philippine law, suitable for standard business relationships and simple data transfers
- Controller-to-Processor DPA: Detailed version for when one company processes data on behalf of another, with specific security measures and audit rights
- Cross-Border DPA: Enhanced version with additional safeguards for international data transfers, meeting Philippine Data Privacy Act requirements for overseas data flow
- Industry-Specific DPA: Customized versions for healthcare, financial services, or technology sectors, incorporating sector-specific compliance requirements
Who should typically use a Data Protection Addendum?
- Data Controllers: Companies and organizations that own and determine how personal data is processed, like banks, hospitals, or tech firms operating in the Philippines
- Data Processors: Service providers and vendors who handle data on behalf of controllers, such as cloud storage providers or outsourcing companies
- Legal Teams: In-house lawyers or external counsel who draft and review Data Protection Addendums to ensure compliance with Philippine privacy laws
- Data Protection Officers: Required by Philippine law to oversee data protection compliance and manage these agreements
- Compliance Managers: Internal staff who implement and monitor adherence to data protection requirements
How do you write a Data Protection Addendum?
- Data Flow Mapping: Document what personal data you'll share, how it moves between parties, and where it's stored
- Security Measures: List current data protection protocols, encryption methods, and access controls in place
- Processing Details: Identify specific data processing activities, duration, and purpose under Philippine law
- Compliance Check: Review Data Privacy Act requirements and NPC guidelines for your industry sector
- Contact Information: Gather details of Data Protection Officers and authorized representatives from all parties
- Incident Response: Outline breach notification procedures and recovery plans before finalizing the addendum
What should be included in a Data Protection Addendum?
- Parties and Roles: Clear identification of data controller, processor, and their respective obligations under Philippine law
- Data Scope: Detailed description of personal information types, processing purposes, and retention periods
- Security Measures: Specific technical and organizational safeguards compliant with NPC guidelines
- Breach Protocol: Mandatory notification procedures and response timelines per Data Privacy Act requirements
- Cross-border Rules: Requirements for international data transfers and overseas processing
- Termination Terms: Data handling procedures upon contract end, including deletion or return protocols
- Audit Rights: Provisions for monitoring compliance and conducting assessments
What's the difference between a Data Protection Addendum and a Data Processing Agreement?
A Data Protection Addendum differs significantly from a Data Processing Agreement in several key ways, though both play crucial roles in Philippine data privacy compliance. While they may seem similar at first glance, understanding their distinct purposes helps choose the right document for your situation.
- Document Structure: A DPA addendum supplements an existing contract, while a Data Processing Agreement stands as an independent agreement
- Scope of Coverage: Addendums typically focus on specific data protection terms within a broader business relationship, while Processing Agreements comprehensively cover all aspects of data handling
- Timing of Implementation: Addendums are often added to existing contracts when data protection needs change, while Processing Agreements are usually established at the start of a data processing relationship
- Legal Framework: Under Philippine law, addendums modify existing contractual obligations, while Processing Agreements create new, standalone data processing obligations
Download our whitepaper on the future of AI in Legal
ұԾ’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; ұԾ’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our for more details and real-time security updates.
Read our Privacy Policy.