Intercompany Data Processing Agreement Template for the United Arab Emirates
Generate a bespoke document
What is a Intercompany Data Processing Agreement?
This Intercompany Data Processing Agreement is designed for use between affiliated companies operating under UAE jurisdiction where one entity processes personal data on behalf of another. The document is essential for compliance with UAE Federal Decree Law No. 45 of 2021 and its Executive Regulations, particularly when sharing personal data within a corporate group. It details the responsibilities of both data controllers and processors, establishes security and confidentiality requirements, and includes specific provisions for cross-border data transfers. The agreement is particularly relevant for multinational companies with UAE operations and those operating in regulated sectors, ensuring proper data protection governance while facilitating necessary business operations between group entities.
About the Intercompany Data Processing Agreement
An Intercompany Data Processing Agreement is a specialized contract that governs how affiliated companies within the same corporate group handle personal data under United Arab Emirates law. This document establishes the legal framework for data sharing between related entities while ensuring compliance with the UAE's comprehensive data protection regime, particularly Federal Decree Law No. 45 of 2021.
When do you need this document?
You need this agreement whenever one UAE company processes personal data on behalf of another affiliated entity within your corporate group. This includes scenarios where a parent company centralizes HR data processing for subsidiaries, when shared service centers handle customer information across multiple group entities, or when UAE operations process data for international affiliates. The agreement is particularly crucial for multinational corporations with complex organizational structures, companies operating in regulated sectors like banking or telecommunications, and businesses that maintain shared IT infrastructure or customer databases across group entities. DIFC-based companies require additional consideration under DIFC Law No. 5 of 2020.
Key legal considerations
Your agreement must clearly define each party's role as either data controller or data processor under UAE law, as these designations carry different legal obligations and liabilities. Security measures must align with the Executive Regulations' requirements, including technical and organizational safeguards, staff training protocols, and incident response procedures. Data transfer provisions are critical, particularly for cross-border sharing within multinational groups, requiring appropriate safeguards and potentially standard contractual clauses. The agreement must address data subject rights, including how requests for access, correction, or deletion will be handled between group entities. Breach notification procedures must comply with UAE requirements, including timelines for reporting to authorities and affected individuals. Audit rights and compliance monitoring mechanisms ensure ongoing adherence to data protection obligations.
Legal requirements in United Arab Emirates
Under Federal Decree Law No. 45 of 2021 and UAE Cabinet Resolution No. 85 of 2022, your agreement must specify the purpose and scope of data processing activities, ensuring they remain within lawful boundaries. Data controllers must maintain ultimate responsibility for compliance, while processors must implement appropriate technical and organizational measures. The agreement must address data retention periods, deletion procedures, and return of data upon contract termination. For companies operating in the DIFC, additional compliance with DIFC data protection laws is mandatory. Cross-border transfers require adequate protection levels or appropriate safeguards, particularly when sharing data with jurisdictions lacking adequate protection findings. The agreement must also comply with UAE Commercial Companies Law regarding inter-company relationships and may need to address electronic signature requirements under the Electronic Transactions and Commerce Law. Regular review and updates ensure ongoing compliance as UAE data protection regulations continue to evolve.
GOVERNING LAW
Applicable law
This Intercompany Data Processing Agreement is drafted to comply with United Arab Emirates law. Key legislation includes:
UAE Cabinet Resolution No. 85 of 2022: Executive Regulations of Federal Decree-Law No. 45/2021, providing detailed implementation requirements for data protection
DIFC Law No. 5 of 2020: Data Protection Law for the Dubai International Financial Centre, relevant if any party operates within the DIFC
Federal Law No. 1 of 2006: Electronic Transactions and Commerce Law, governing electronic communications and digital signatures in commercial relationships
Federal Law No. 2 of 2015: Commercial Companies Law, governing relationships between companies and corporate entities in the UAE
Federal Decree Law No. 34 of 2021: Combating Rumors and Cybercrimes Law, containing provisions relevant to data security and cybersecurity requirements
Federal Law No. 4 of 2012: Competition Law, relevant for intercompany relationships and data sharing arrangements between related entities
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it