Data Transfer Agreements: When You Need One and What to Include

Alex Solo
byAlex Solo12 min read
Contents

Plenty of New Zealand businesses send personal information offshore without realising they have a data transfer issue. It often happens when you sign up to cloud software, outsource support, use an overseas payroll provider, or let a parent company access customer records from another country.

The common mistakes are usually the same: relying on a supplier's standard terms without reading the privacy clauses, assuming a privacy policy or privacy notice alone is enough, and failing to check whether the overseas recipient can actually protect the information to a similar standard.

That matters because once personal information leaves your hands, your business can still carry legal and commercial risk. A weak contract can leave you exposed if data is misused, disclosed without authority, or held in a country with weaker protections. This guide explains when data transfer agreements are needed, what they should include, and the legal issues New Zealand businesses should check before they sign.

Overview

A data transfer agreement is a contract that sets the rules for sending personal information from one organisation to another, especially across borders. For New Zealand businesses, the key question is not just whether data is being transferred, but who controls it, where it is going, and whether the recipient is required to protect it in a way that lines up with the Privacy Act 2020.

  • Identify whether personal information is being transferred, accessed remotely, stored offshore, or disclosed to a separate business.
  • Work out each party's role, including whether the recipient is acting as your service provider or using the data for its own purposes.
  • Check whether the overseas recipient is subject to comparable privacy safeguards or whether contract terms need to fill the gap.
  • Review restrictions on use, disclosure, onward transfers, retention, deletion, and security standards.
  • Make sure the agreement deals with data breaches, audit rights, subcontractors, and end of contract return or destruction.
  • Match the agreement to your privacy notices, internal practices, and the promises you make to customers, staff, and suppliers.

What Data Transfer Agreements Means For New Zealand Businesses

For a New Zealand business, a data transfer agreement is often the document that turns a vague privacy promise into enforceable rules. If personal information is moving to an overseas provider, affiliate, platform, or commercial partner, this is usually where the practical protections sit.

What counts as a data transfer?

A transfer is not limited to emailing a spreadsheet overseas. It can include giving a software provider access to your customer database, storing staff records on foreign servers, sharing leads with an offshore sales team, or letting a third party analyse user behaviour using identifiable information.

Founders often miss this point when the information stays visible in the same platform. If an overseas vendor can access, process, back up, or host the data, there may still be a transfer or overseas disclosure issue to assess before you sign a contract.

Why this matters under New Zealand privacy law

The Privacy Act 2020 matters because New Zealand businesses cannot treat offshore data sharing as a purely operational choice. Information Privacy Principle 12 deals with disclosures of personal information outside New Zealand, and it pushes businesses to ask whether the overseas recipient is subject to laws or binding safeguards that provide comparable protection.

In plain English, that means you should not assume an overseas supplier's location is irrelevant. Before you accept the provider's standard terms, you need to understand whether the recipient is in a jurisdiction with comparable safeguards, whether the individual has authorised the disclosure, or whether contract terms are needed to protect the information properly.

When do you usually need a data transfer agreement?

You usually need one when personal information is being shared with another entity and the transfer is material enough that you want clear legal rules around use, storage, security, and liability. In practice, common founder moments include:

  • before you sign with a cloud software provider that stores customer or employee data overseas
  • before you appoint an offshore payroll, HR, finance, or IT support provider
  • before you share customer information with a parent company, subsidiary, or franchise network in another country
  • before you let an overseas marketing agency, analytics provider, or CRM consultant access identifiable personal information
  • before you rely on a verbal promise from a supplier that it is “privacy compliant”

You may also need a tailored data transfer clause inside a broader services agreement, SaaS contract, outsourcing agreement, or group company arrangement. It does not always have to be a standalone document, but the terms need to be clear and enforceable somewhere.

Data transfer agreement or data processing agreement?

These terms are often used interchangeably, but they are not always identical. A data processing agreement usually focuses on a service provider processing personal information on your behalf. A data transfer agreement may be broader and deal specifically with cross border disclosure, onward sharing, and the conditions under which information can leave New Zealand.

The label matters less than the content. What matters is whether the contract actually covers the privacy and security issues created by the transfer.

What should the agreement include?

A usable data transfer agreement should spell out the rules that matter when things go wrong, not just repeat general privacy statements. At a minimum, most businesses should expect to see:

  • the parties involved, including any affiliates or subcontractors who may access the information
  • the categories of personal information being transferred, such as customer details, payment-related data, employee records, or health information where relevant
  • the purpose of the transfer and limits on how the recipient can use the data
  • security obligations, including technical and organisational measures expected from the recipient
  • restrictions on onward transfers to other countries or providers
  • rules for retaining, returning, deleting, or destroying information at the end of the arrangement
  • breach notification timeframes and cooperation obligations
  • audit, reporting, or evidence rights so you can verify compliance
  • liability, indemnity, and risk allocation terms if misuse or unauthorised disclosure occurs
  • governing law and dispute clauses that are commercially workable for both sides

If the arrangement involves sensitive information, high volumes of customer data, or a provider with multiple subcontractors, the detail matters even more. This is where founders often get caught, because a short standard annex rarely covers the real operational risk.

Before you sign a data transfer agreement, check whether the document actually matches the way your business handles information. A contract that looks fine on paper can still fail if your team, systems, and privacy notices say something different.

1. Who is disclosing the information, and to whom?

You need a clear map of the data flow. That means identifying the New Zealand entity collecting the information, the overseas recipient, any parent or group companies involved, and any subcontractors who will also receive access.

This sounds basic, but it is often missed in growing businesses with multiple brands or related entities. If the wrong entity signs, the contract may not protect the business that actually collected the data.

2. What personal information is involved?

The legal and commercial risk depends heavily on the type of information being transferred. Names and email addresses may still require protection, but employee files, identity documents, financial details, or health-related information usually call for stricter controls.

Before you sign, list the categories of data involved using practical business language. For example:

  • customer contact details and order history
  • staff payroll and leave records
  • supplier contact information
  • support tickets containing account details
  • marketing data linked to identifiable users

3. Is the transfer allowed under your existing privacy position?

Your privacy statement, collection notices, sign-up forms, and internal policies should line up with what the contract allows. If your business tells people their data will only be used for one purpose, but the provider contract allows broader analytics, product improvement, or group-wide sharing, you have a problem before any transfer even happens.

This is not just a drafting issue. It can become a trust issue with customers, a staff issue with employee information, and a compliance issue if your disclosures are inaccurate or incomplete.

4. Does the overseas recipient have comparable safeguards?

One of the main legal questions for New Zealand businesses is whether the overseas recipient is subject to privacy laws or binding arrangements that provide comparable protection. A contract is often part of that analysis.

Before you accept the provider's standard terms, check:

  • whether the supplier says which countries data will be stored in or accessed from
  • whether it commits to privacy obligations comparable to New Zealand standards
  • whether it can move the data to other countries without telling you
  • whether its subcontractor chain is transparent
  • whether it offers meaningful remedies if it breaches those obligations

5. What security standard is actually promised?

Broad statements like “industry standard security” are often too vague on their own. You want enough detail to understand what the provider is required to do, especially if the data is commercially sensitive or regulated by contract.

Useful security points may include:

  • access controls and user permissions
  • encryption in transit and at rest where appropriate
  • multi-factor authentication for administrative access
  • logging and monitoring of unauthorised activity
  • secure backup and recovery processes
  • staff confidentiality obligations and training

6. What happens if there is a privacy breach?

The contract should not leave you guessing about who does what after a breach. Time matters, especially if your business may need to assess whether a notifiable privacy breach has occurred and respond quickly.

Look for clauses covering:

  • how soon the recipient must notify you after discovering a breach
  • what information it must provide about the incident
  • whether it must help with investigation, containment, and remediation
  • who controls communications to affected individuals and regulators
  • who bears the cost if the breach was caused by the recipient's failure

7. Can the recipient use subcontractors?

Most modern tech and outsourcing providers rely on sub-processors or subcontractors. The main risk is that your agreement carefully controls one recipient, but says little about the chain of third parties behind it.

Before you sign, check whether subcontracting is allowed only with notice or approval, whether equivalent obligations flow down to those providers, and whether the original recipient remains responsible for their acts and omissions.

8. How does the arrangement end?

Data transfer agreements often get negotiated at the start and ignored at the end. That is risky. If the relationship finishes, you need to know whether personal information will be returned, deleted, anonymised, or retained for a limited legal reason.

The end of contract clause should deal with:

  • when data must be returned or destroyed
  • what format any returned data will take
  • whether backups are also deleted or only retained for a limited period
  • whether the recipient can keep any information for legal compliance reasons
  • what certification or evidence of deletion can be provided

9. Do the liability clauses leave you carrying all the risk?

Many standard supplier agreements cap liability very low, exclude consequential loss widely, and avoid any real responsibility for subcontractors or cyber incidents. That may not be commercially acceptable if the vendor is handling large volumes of personal information.

This does not always mean the vendor will agree to unlimited liability. It does mean you should test whether the cap, exclusions, indemnities, insurance obligations, and insurance position fairly reflect the data risk before you sign.

Common Mistakes With Data Transfer Agreements

The biggest mistake is treating a data transfer agreement as a routine procurement document. If personal information is involved, the contract needs legal, privacy, and operational review, not just a quick contract review or commercial sign-off.

Assuming your privacy policy does all the work

A privacy policy helps explain what your business does, but it does not automatically bind the overseas recipient. If the contract is silent, your policy will not fix poor security terms, missing breach obligations, or broad rights for the recipient to use data for its own purposes.

Accepting standard terms without checking offshore disclosures

Many software and platform providers use standard documents drafted for multiple countries. Those terms may not line up neatly with New Zealand privacy expectations, especially around overseas disclosures and comparable safeguards.

This is where SMEs often get caught before they spend money on setup or migration. The product may be a good operational fit, but the data clauses can still need negotiation or side terms.

Failing to distinguish between hosting and independent use

A provider that stores or processes information only for your business creates one type of risk. A partner that receives the data and uses it for its own analytics, cross-selling, or product development creates another. The contract should reflect that difference.

If you treat every recipient like a passive processor, you may miss permissions, disclosures, and liability issues that come with a more independent use model.

Ignoring onward transfers

One overseas recipient can quickly become five or ten if the provider uses affiliates, cloud hosts, support desks, and analytics tools in different countries. If the agreement does not control onward transfers, your original review may become outdated almost immediately.

Leaving security language too vague

General promises sound reassuring, but they can be hard to enforce. If security is commercially important, spell out the minimum standards, reporting obligations, and consequences of failing to maintain them.

Overlooking practical access and deletion issues

Some businesses only discover the gaps when they want to switch providers or respond to a privacy request. If the agreement does not deal with export formats, response times, assistance obligations, and deletion steps, your business may face avoidable cost and delay.

Not matching the contract to internal practice

If your agreement says only authorised personnel can access the data, but your internal processes are loose, the contract will not save you. The legal document should support a real operating model, including staff access controls, vendor management, and incident response processes.

Relying on verbal assurances

Founders are often told that a provider is certified, secure, or “fully compliant”. Unless the contract reflects the promises that matter, those statements may offer little help later. Before you rely on a verbal promise, get the relevant commitments written into the agreement or supporting documents.

FAQs

Does every overseas software provider require a separate data transfer agreement?

Not always as a standalone document, but you should have enforceable data transfer or processing terms somewhere in the contract set. If personal information is being hosted, accessed, or processed offshore, the legal terms need to address that properly.

Can we rely on a supplier's global privacy terms?

Sometimes, but only if those terms actually cover the New Zealand privacy issues that matter to your business. Many standard terms are broad, provider-friendly, and light on liability, subcontractor controls, or meaningful breach support.

What if the data stays in New Zealand but support staff overseas can access it?

That can still raise overseas disclosure or access issues. The physical server location is not the only question. Remote access by offshore personnel may still need to be assessed and covered by contract terms.

Do employee records need the same attention as customer data?

Yes. Employee personal information can be highly sensitive, especially where payroll, identity, health, or performance information is involved. Businesses should not treat staff data as lower risk simply because it is internal.

Should a small business worry about this, or is it only for larger companies?

Small businesses should worry about it too, especially if they use offshore SaaS tools, outsourced admin support, or international group structures. The legal principles are relevant even if the business is still growing.

Key Takeaways

  • Data transfer agreements matter when personal information is shared, hosted, accessed, or processed by another organisation, especially offshore.
  • New Zealand businesses should assess overseas disclosures carefully under the Privacy Act 2020, including whether the recipient is subject to comparable safeguards or binding contractual protections.
  • A workable agreement should cover use restrictions, security, subcontractors, breach response, onward transfers, retention, deletion, and liability.
  • Standard supplier terms are often not enough on their own, particularly where the provider can use subcontractors widely or limits its responsibility heavily.
  • The contract should line up with your privacy notices, internal practices, and the way your team actually handles customer and employee information.
  • It is worth reviewing data transfer terms before you sign, before you accept the provider's standard terms, and before you rely on a verbal promise about privacy compliance.

If you want help with privacy law compliance, supplier contract terms, offshore disclosure clauses, and breach response obligations, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

When should you formalise this?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.