Controller Processor Agreement Template for the United Arab Emirates
Generate a bespoke document
What is a Controller Processor Agreement?
The Controller Processor Agreement is essential for organizations engaging in data processing activities within the UAE jurisdiction. This document is required under Federal Decree-Law No. 45/2021 whenever a data controller engages a processor to handle personal data on their behalf. The agreement ensures compliance with UAE data protection requirements, including specific provisions for data security, breach notification, and cross-border transfers. It's particularly important for businesses operating in UAE mainland and free zones, as it helps demonstrate compliance with local regulations while providing a framework for secure and lawful data processing activities. The agreement should be customized based on the specific processing activities, incorporating relevant requirements from both federal law and applicable free zone regulations.
About the Controller Processor Agreement
A Controller Processor Agreement is a legally binding contract required under United Arab Emirates data protection law when you engage a third-party service provider to process personal data on your behalf. This agreement establishes clear responsibilities between data controllers and processors, ensuring compliance with Federal Decree-Law No. 45/2021 and related regulations. Whether you're outsourcing HR functions, engaging cloud service providers, or working with marketing agencies, this document protects your organization from regulatory violations and defines accountability for data security.
When do you need this document?
You need a Controller Processor Agreement whenever you engage external service providers to process personal data as part of your business operations. This includes scenarios such as outsourcing payroll processing to accounting firms, using cloud storage providers for customer data, engaging marketing agencies for email campaigns, or contracting IT support companies that access employee information. The agreement is also required when working with sub-processors, ensuring the entire data processing chain maintains compliance with UAE data protection standards. Free zone entities operating under DIFC or ADGM regulations may require additional specific clauses to meet their jurisdictional requirements.
Key legal considerations
Your agreement must clearly define the scope and purpose of data processing activities, specifying categories of personal data and processing operations permitted. Security measures are critical, requiring processors to implement appropriate technical and organizational safeguards to protect personal data integrity and confidentiality. The document should establish clear breach notification procedures, requiring processors to notify controllers within specific timeframes outlined in Cabinet Resolution No. 100/2022. Data retention periods must be defined, along with secure deletion procedures when processing purposes are fulfilled. Cross-border transfer provisions are essential if data leaves UAE jurisdiction, requiring adequate protection measures and compliance with international transfer restrictions. The agreement should also address audit rights, allowing controllers to verify processor compliance with contractual obligations.
Legal requirements in United Arab Emirates
Under Federal Decree-Law No. 45/2021, controller-processor agreements must include specific mandatory provisions to ensure regulatory compliance. These include detailed data processing instructions, security requirements aligned with the law's technical safeguards, and breach notification procedures that meet the 72-hour notification requirement to the UAE Data Protection Authority. The agreement must specify data subject rights procedures, ensuring processors support controllers in responding to access, rectification, and deletion requests. For organizations operating in Dubai International Financial Centre, compliance with DIFC Data Protection Law No. 5 of 2020 may require additional contractual provisions. Similarly, Abu Dhabi Global Market entities must consider ADGM Data Protection Regulations 2021 requirements. The document should address data localization requirements where applicable and ensure compliance with any sector-specific regulations governing your industry within the UAE framework.
GOVERNING LAW
Applicable law
This Controller Processor Agreement is drafted to comply with United Arab Emirates law. Key legislation includes:
Cabinet Resolution No. 100/2022: Executive regulations implementing Federal Decree-Law No. 45/2021, providing detailed requirements for data processing agreements and compliance measures.
DIFC Data Protection Law No. 5 of 2020: Specific data protection regulations for the Dubai International Financial Centre free zone, which may be relevant if either party operates in the DIFC.
ADGM Data Protection Regulations 2021: Abu Dhabi Global Market's data protection regulations, which may be applicable if either party operates in the ADGM free zone.
UAE Federal Law No. 2 of 2019: Concerning the Use of Information and Communication Technology in Healthcare, relevant if the data processing involves health-related information.
UAE Federal Law No. 5 of 2012: Cybercrime Law that includes provisions related to privacy and confidentiality of electronic information, which may impact data processing requirements.
UAE Consumer Protection Law Federal Law No. 15 of 2020: Relevant when processing consumer data, including provisions for protecting consumer privacy and data rights.
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it