Data Sharing Agreement Controller To Processor Template for the United Arab Emirates
Generate a bespoke document
What is a Data Sharing Agreement Controller To Processor?
This Data Sharing Agreement Controller To Processor is essential for organizations operating under UAE jurisdiction that engage third parties to process personal data on their behalf. The agreement ensures compliance with UAE Federal Decree-Law No. 45/2021 and its Executive Regulations, which mandate specific requirements for controller-processor relationships. It should be used whenever a data controller outsources personal data processing activities to a third-party processor, whether for services such as cloud storage, payment processing, HR management, or other data processing activities. The document includes crucial provisions for data security, confidentiality, breach notification, audit rights, and data subject rights management, while also addressing specific UAE regulatory requirements such as data localization and cross-border transfer restrictions where applicable.
About the Data Sharing Agreement Controller To Processor
A Data Sharing Agreement Controller To Processor is a legally binding contract that establishes the relationship between organizations that collect personal data and third-party service providers that process that data under UAE jurisdiction. This agreement ensures compliance with Federal Decree-Law No. 45/2021, the UAE's comprehensive Personal Data Protection Law, which mandates specific obligations for both data controllers and processors.
When do you need this document?
You need this agreement whenever your organization engages a third party to process personal data on your behalf. This includes outsourcing activities such as cloud storage services, payment processing, customer relationship management, HR and payroll services, marketing automation, or IT support services. The document is also required when working with international service providers who will process UAE residents' personal data, as it addresses cross-border transfer requirements under Cabinet Resolution No. 85/2022. Healthcare organizations processing medical data must ensure the agreement complies with Federal Law No. 2 of 2019 regarding ICT use in healthcare.
Key legal considerations
Your agreement must clearly define the scope and purpose of data processing activities, specifying what categories of personal data will be processed and for what legitimate purposes. Include detailed data security measures that align with UAE cybercrime prevention requirements under Federal Law No. 5 of 2012. The contract should establish clear data retention periods, deletion procedures, and breach notification protocols that meet the 72-hour reporting requirement under UAE law. Ensure the agreement includes audit rights, allowing you to monitor the processor's compliance with data protection obligations. Address data subject rights management, including how the processor will assist with access requests, corrections, and deletion demands. Include specific provisions for data localization requirements if applicable to your business sector.
Legal requirements in United Arab Emirates
Under Federal Decree-Law No. 45/2021 and Cabinet Resolution No. 85/2022, your agreement must demonstrate that the processor provides sufficient guarantees regarding technical and organizational security measures. The contract must be in writing and include specific mandatory clauses regarding data processing instructions, confidentiality obligations, and assistance with data subject rights. If processing involves cross-border transfers, ensure the agreement addresses adequacy decisions or includes appropriate safeguards as required by UAE regulations. For businesses operating in the Dubai International Financial Centre, additional compliance with DIFC Data Protection Law No. 5 may be required. The agreement should specify governing law as UAE federal law and designate UAE courts for dispute resolution. Include provisions for processor liability and indemnification to protect your organization from regulatory penalties resulting from processor non-compliance.
GOVERNING LAW
Applicable law
This Data Sharing Agreement Controller To Processor is drafted to comply with United Arab Emirates law. Key legislation includes:
Cabinet Resolution No. 85/2022: Executive Regulations of the UAE Personal Data Protection Law, providing detailed implementation requirements and compliance guidelines
Federal Law No. 1 of 2006: Electronic Commerce and Transactions Law governing electronic transactions and digital signatures in the UAE
Federal Law No. 5 of 2012: Cybercrime Law addressing data security and cybercrime prevention, relevant for data protection measures
Federal Law No. 2 of 2019: Law on the Use of ICT in Healthcare, specific to health data processing if medical data is involved
DIFC Data Protection Law No. 5 of 2020: While specific to Dubai International Financial Centre, often used as a reference point for best practices in data protection
UAE Information Assurance Standards: Standards issued by the UAE National Electronic Security Authority for information security requirements
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it