Data Controller Agreement Template for the United Arab Emirates
Generate a bespoke document
What is a Data Controller Agreement?
This Data Controller Agreement is essential for organizations operating in the UAE that collect, process, or control personal data. It ensures compliance with UAE Federal Decree-Law No. 45 of 2021, which establishes comprehensive data protection requirements across the UAE. The agreement is particularly relevant for businesses subject to UAE mainland jurisdiction, while also considering specific requirements for free zones such as DIFC and ADGM. It addresses crucial aspects of data protection including security measures, breach notifications, cross-border transfers, and data subject rights, incorporating both federal and local regulatory requirements. The document is designed to help organizations demonstrate compliance with UAE data protection laws while maintaining operational efficiency.
Trusted by high-performance teams
About the Data Controller Agreement
A Data Controller Agreement is a critical legal document that establishes the framework for how organizations handle personal data in the United Arab Emirates. Under UAE Federal Decree-Law No. 45 of 2021, any entity that determines the purposes and means of processing personal data must have clear contractual arrangements that define responsibilities, obligations, and compliance requirements.
When do you need this document?
You need a Data Controller Agreement when your organization processes personal data of UAE residents or operates within UAE jurisdiction. This includes situations where you engage service providers to process data on your behalf, transfer data across borders, or work with sub-processors. The agreement is essential for multinational companies with UAE operations, local businesses handling customer data, healthcare providers managing patient information, and financial institutions processing client data. Free zone entities in DIFC and ADGM require specific provisions that align with their respective data protection regulations.
Key legal considerations
Your agreement must clearly define the roles of data controllers and processors, specify lawful bases for processing under UAE law, and establish robust data security measures. Key clauses should address data retention periods, breach notification procedures within 72 hours to authorities, and mechanisms for handling data subject rights requests. The agreement must include provisions for conducting data protection impact assessments for high-risk processing activities and maintaining records of processing activities. Cross-border data transfer clauses are crucial, as they must demonstrate adequate protection levels or implement appropriate safeguards. You should also include termination clauses that specify data deletion or return obligations.
Legal requirements in United Arab Emirates
Under Federal Decree-Law No. 45 of 2021, data controllers must implement technical and organizational measures to ensure data security and confidentiality. Your agreement must comply with specific requirements for sensitive personal data, including health data under UAE Federal Law No. 2 of 2019. If operating in DIFC, you must adhere to DIFC Law No. 5 of 2020, which follows GDPR-like principles with stricter consent requirements. ADGM entities must comply with ADGM Data Protection Regulations 2021, which include specific provisions for automated decision-making. Financial institutions must also consider UAE Cabinet Resolution No. 31 of 2019 regarding cybersecurity requirements. The agreement should designate a Data Protection Officer where required and establish clear reporting lines to relevant regulatory authorities including the UAE Data Office and applicable free zone authorities.
GOVERNING LAW
Applicable law
This Data Controller Agreement is drafted to comply with United Arab Emirates law. Key legislation includes:
DIFC Law No. 5 of 2020: Data Protection Law for the Dubai International Financial Centre, which follows GDPR-like principles and applies to companies operating in DIFC
ADGM Data Protection Regulations 2021: Comprehensive data protection regulations for Abu Dhabi Global Market, applicable to entities operating within ADGM
UAE Federal Law No. 2 of 2019: Concerning the Use of Information and Communication Technology in Healthcare, which includes provisions for health data protection
UAE Cabinet Resolution No. 31 of 2019: Concerning Cybersecurity Regulations for Financial Institutions, which includes data protection requirements for the financial sector
UAE Federal Law No. 15 of 2020: Consumer Protection Law that includes provisions relating to consumer data protection and privacy
UAE Penal Code: Contains provisions relating to privacy violations and unauthorized disclosure of confidential information
UAE Federal Law No. 5 of 2012: Cybercrime Law that includes provisions for protecting electronic data and information systems
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

