Controller Processor Agreement Template for Singapore
Generate a bespoke document
What is a Controller Processor Agreement?
The Controller Processor Agreement is essential for organizations operating in Singapore that outsource personal data processing activities. This agreement ensures compliance with the Personal Data Protection Act 2012 (PDPA) and related regulations by clearly defining the roles, responsibilities, and obligations of both controllers and processors. It covers crucial aspects such as data security measures, breach notification procedures, cross-border transfer requirements, and specific compliance obligations under Singapore law. The agreement is particularly important given Singapore's strict data protection regime and significant penalties for non-compliance.
About the Controller Processor Agreement
When your Singapore-based organization outsources personal data processing to third parties, you need a Controller Processor Agreement to ensure legal compliance and protect both parties. This contract establishes clear boundaries between data controllers and processors under Singapore's Personal Data Protection Act 2012 (PDPA), defining who is responsible for what aspects of data handling and protection.
When do you need this document?
You must have a Controller Processor Agreement whenever you engage external service providers to process personal data on your behalf. This includes cloud storage providers, payroll processing companies, marketing agencies handling customer data, IT support services accessing employee information, or any third-party vendor that will handle personal data as part of their services. The agreement is also required when Singapore companies transfer personal data processing to overseas entities, ensuring compliance with cross-border transfer requirements under the PDPA.
Key legal considerations
Your agreement must clearly define the scope and purpose of data processing activities, ensuring the processor only handles data as specifically authorized. Include comprehensive security measures that align with PDPA requirements, covering technical and organizational safeguards for data protection. Establish clear breach notification procedures, requiring the processor to notify you immediately of any security incidents. Address data retention and deletion obligations, specifying how long data can be stored and secure disposal methods. Include provisions for data subject access rights, ensuring the processor assists with individual requests for access, correction, or deletion of personal data.
Legal requirements in Singapore
Under the PDPA 2012 and Personal Data Protection Regulations 2021, your agreement must comply with specific Singapore requirements. The processor must implement appropriate security arrangements to prevent unauthorized access, collection, use, or disclosure of personal data. For cross-border transfers, ensure compliance with PDPA transfer restrictions and consider adequacy decisions or binding corporate rules where applicable. Include audit rights allowing you to verify the processor's compliance with data protection obligations. The agreement must address the processor's obligation to assist with Data Protection Impact Assessments when required under PDPC guidelines. Ensure breach notification timelines align with PDPA requirements, typically requiring notification within 72 hours of discovering a data breach that poses significant harm risk.
GOVERNING LAW
Applicable law
This Controller Processor Agreement is drafted to comply with Singapore law. Key legislation includes:
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it