Controller Processor Agreement Template for the United Arab Emirates

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Controller Processor Agreement?

The Controller Processor Agreement is essential for organizations engaging in data processing activities within the UAE jurisdiction. This document is required under Federal Decree-Law No. 45/2021 whenever a data controller engages a processor to handle personal data on their behalf. The agreement ensures compliance with UAE data protection requirements, including specific provisions for data security, breach notification, and cross-border transfers. It's particularly important for businesses operating in UAE mainland and free zones, as it helps demonstrate compliance with local regulations while providing a framework for secure and lawful data processing activities. The agreement should be customized based on the specific processing activities, incorporating relevant requirements from both federal law and applicable free zone regulations.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Controller Processor Agreement

A Controller Processor Agreement is a legally binding contract required under United Arab Emirates data protection law when you engage a third-party service provider to process personal data on your behalf. This agreement establishes clear responsibilities between data controllers and processors, ensuring compliance with Federal Decree-Law No. 45/2021 and related regulations. Whether you're outsourcing HR functions, engaging cloud service providers, or working with marketing agencies, this document protects your organization from regulatory violations and defines accountability for data security.

When do you need this document?

You need a Controller Processor Agreement whenever you engage external service providers to process personal data as part of your business operations. This includes scenarios such as outsourcing payroll processing to accounting firms, using cloud storage providers for customer data, engaging marketing agencies for email campaigns, or contracting IT support companies that access employee information. The agreement is also required when working with sub-processors, ensuring the entire data processing chain maintains compliance with UAE data protection standards. Free zone entities operating under DIFC or ADGM regulations may require additional specific clauses to meet their jurisdictional requirements.

Key legal considerations

Your agreement must clearly define the scope and purpose of data processing activities, specifying categories of personal data and processing operations permitted. Security measures are critical, requiring processors to implement appropriate technical and organizational safeguards to protect personal data integrity and confidentiality. The document should establish clear breach notification procedures, requiring processors to notify controllers within specific timeframes outlined in Cabinet Resolution No. 100/2022. Data retention periods must be defined, along with secure deletion procedures when processing purposes are fulfilled. Cross-border transfer provisions are essential if data leaves UAE jurisdiction, requiring adequate protection measures and compliance with international transfer restrictions. The agreement should also address audit rights, allowing controllers to verify processor compliance with contractual obligations.

Legal requirements in United Arab Emirates

Under Federal Decree-Law No. 45/2021, controller-processor agreements must include specific mandatory provisions to ensure regulatory compliance. These include detailed data processing instructions, security requirements aligned with the law's technical safeguards, and breach notification procedures that meet the 72-hour notification requirement to the UAE Data Protection Authority. The agreement must specify data subject rights procedures, ensuring processors support controllers in responding to access, rectification, and deletion requests. For organizations operating in Dubai International Financial Centre, compliance with DIFC Data Protection Law No. 5 of 2020 may require additional contractual provisions. Similarly, Abu Dhabi Global Market entities must consider ADGM Data Protection Regulations 2021 requirements. The document should address data localization requirements where applicable and ensure compliance with any sector-specific regulations governing your industry within the UAE framework.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it