Joint Controller Agreement Template for the United Arab Emirates
Generate a bespoke document
What is a Joint Controller Agreement?
This Joint Controller Agreement is essential when two or more organizations jointly determine how and why personal data is processed in the UAE. It is specifically designed to comply with Federal Decree-Law No. 45 of 2021 on Personal Data Protection, as well as applicable free zone regulations. The document should be used when organizations share decision-making authority over data processing activities, need to allocate responsibilities for compliance with UAE data protection laws, or operate collaborative projects involving personal data processing. It covers crucial aspects such as roles and responsibilities, data security measures, breach notification procedures, and mechanisms for ensuring data subject rights, all within the context of UAE's legal framework and business environment.
About the Joint Controller Agreement
A Joint Controller Agreement is a critical legal document that establishes the framework when two or more organizations jointly determine the purposes and means of processing personal data in the United Arab Emirates. Under Federal Decree-Law No. 45 of 2021, joint controllers must clearly define their respective roles and responsibilities to ensure compliance with UAE data protection requirements.
When do you need this document?
You need a Joint Controller Agreement when your organization collaborates with another entity in processing personal data where both parties have decision-making authority. This includes joint marketing campaigns where customer data is shared, research partnerships involving personal information, shared customer loyalty programs, or collaborative projects between UAE companies and international partners. The agreement is particularly important in free zones like DIFC and ADGM, where additional regulatory requirements apply alongside federal law.
Key legal considerations
The agreement must clearly allocate responsibilities for data protection compliance between controllers, including data security measures, breach notification procedures, and handling data subject requests. Under UAE law, both controllers remain jointly liable for compliance failures, making clear responsibility allocation crucial. The document should address cross-border data transfers, especially important given the UAE's role as a regional business hub. You must also consider the appointment of Data Protection Officers where required, local representative obligations, and specific requirements for processing sensitive personal data categories under Federal Decree-Law No. 45 of 2021.
Legal requirements in United Arab Emirates
UAE data protection law requires joint controllers to establish transparent arrangements through a written agreement that complies with Federal Decree-Law No. 45 of 2021. If operating in free zones, additional compliance with DIFC Law No. 5 of 2020 or ADGM Data Protection Regulations 2021 may be required. The agreement must address data subject rights procedures, including access, rectification, and erasure requests, with clear timelines for response. For healthcare data, compliance with Federal Law No. 2 of 2019 concerning healthcare ICT use is mandatory. The document should also specify which controller will serve as the primary contact point for regulatory authorities and data subjects, ensuring seamless compliance with UAE notification and registration requirements.
GOVERNING LAW
Applicable law
This Joint Controller Agreement is drafted to comply with United Arab Emirates law. Key legislation includes:
DIFC Law No. 5 of 2020: Dubai International Financial Centre Data Protection Law, which provides specific requirements for data protection in the DIFC free zone and aligns with GDPR principles
ADGM Data Protection Regulations 2021: Abu Dhabi Global Market's data protection regulations that govern data processing activities within the ADGM free zone
UAE Federal Law No. 2 of 2019: Concerning the Use of Information and Communication Technology in Healthcare, relevant for health data processing arrangements
UAE Federal Law No. 1 of 2006: Electronic Transactions and Commerce Law that provides framework for electronic transactions and related data processing
UAE Federal Law No. 5 of 1985: Civil Transactions Law (Civil Code) providing general contractual principles applicable to joint controller relationships
UAE Federal Law No. 2 of 2015: Commercial Companies Law governing business relationships and joint ventures which may be relevant to controller relationships
UAE Consumer Protection Law Federal Law No. 15 of 2020: Relevant when joint controllers process consumer data or engage in consumer-facing activities
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it