Data Controller Agreement Template for the United Arab Emirates

Generate a bespoke document

What is a Data Controller Agreement?

This Data Controller Agreement is essential for organizations operating in the UAE that collect, process, or control personal data. It ensures compliance with UAE Federal Decree-Law No. 45 of 2021, which establishes comprehensive data protection requirements across the UAE. The agreement is particularly relevant for businesses subject to UAE mainland jurisdiction, while also considering specific requirements for free zones such as DIFC and ADGM. It addresses crucial aspects of data protection including security measures, breach notifications, cross-border transfers, and data subject rights, incorporating both federal and local regulatory requirements. The document is designed to help organizations demonstrate compliance with UAE data protection laws while maintaining operational efficiency.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

United Arab Emirates

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Controller Agreement

A Data Controller Agreement is a critical legal document that establishes the framework for how organizations handle personal data in the United Arab Emirates. Under UAE Federal Decree-Law No. 45 of 2021, any entity that determines the purposes and means of processing personal data must have clear contractual arrangements that define responsibilities, obligations, and compliance requirements.

When do you need this document?

You need a Data Controller Agreement when your organization processes personal data of UAE residents or operates within UAE jurisdiction. This includes situations where you engage service providers to process data on your behalf, transfer data across borders, or work with sub-processors. The agreement is essential for multinational companies with UAE operations, local businesses handling customer data, healthcare providers managing patient information, and financial institutions processing client data. Free zone entities in DIFC and ADGM require specific provisions that align with their respective data protection regulations.

Key legal considerations

Your agreement must clearly define the roles of data controllers and processors, specify lawful bases for processing under UAE law, and establish robust data security measures. Key clauses should address data retention periods, breach notification procedures within 72 hours to authorities, and mechanisms for handling data subject rights requests. The agreement must include provisions for conducting data protection impact assessments for high-risk processing activities and maintaining records of processing activities. Cross-border data transfer clauses are crucial, as they must demonstrate adequate protection levels or implement appropriate safeguards. You should also include termination clauses that specify data deletion or return obligations.

Legal requirements in United Arab Emirates

Under Federal Decree-Law No. 45 of 2021, data controllers must implement technical and organizational measures to ensure data security and confidentiality. Your agreement must comply with specific requirements for sensitive personal data, including health data under UAE Federal Law No. 2 of 2019. If operating in DIFC, you must adhere to DIFC Law No. 5 of 2020, which follows GDPR-like principles with stricter consent requirements. ADGM entities must comply with ADGM Data Protection Regulations 2021, which include specific provisions for automated decision-making. Financial institutions must also consider UAE Cabinet Resolution No. 31 of 2019 regarding cybersecurity requirements. The agreement should designate a Data Protection Officer where required and establish clear reporting lines to relevant regulatory authorities including the UAE Data Office and applicable free zone authorities.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it