Controller To Controller DPA Template for Singapore
Generate a bespoke document
What is a Controller To Controller DPA?
The Controller to Controller DPA is essential when two organizations acting as independent data controllers need to share personal data in Singapore. This agreement type is particularly important under Singapore's PDPA framework, which requires organizations to implement appropriate data protection measures when handling personal data. The document outlines specific responsibilities, security requirements, breach notification procedures, and compliance obligations for both controllers, ensuring lawful and secure data sharing practices while maintaining individual privacy rights.
About the Controller To Controller DPA
A Controller To Controller Data Protection Agreement (DPA) is a legal contract between two organizations that both act as independent data controllers under Singapore's Personal Data Protection Act 2012 (PDPA). This agreement establishes the terms and conditions for sharing personal data between the parties while ensuring compliance with Singapore's data protection framework and maintaining the privacy rights of individuals whose data is being processed.
When do you need this document?
You need a Controller To Controller DPA when your organization plans to share personal data with another company that will use that data for its own independent purposes. Common scenarios include business partnerships where customer lists are shared, joint marketing initiatives between companies, mergers and acquisitions involving data transfer, or collaborative research projects. Under the PDPA, both organizations remain independently responsible for their data processing activities, making this agreement essential for defining respective obligations and ensuring regulatory compliance.
Key legal considerations
The agreement must clearly define the scope and purpose of data sharing, ensuring both parties understand their roles as independent data controllers. Critical clauses include data security measures that meet PDPA standards, breach notification procedures that comply with the Personal Data Protection (Notification of Data Breaches) Regulations 2021, and provisions for international data transfers if applicable. The document should specify retention periods, data minimization principles, and individual rights management procedures. Both parties must ensure they have appropriate consent or legitimate grounds for processing under the PDPA's consent framework or other lawful bases for processing.
Legal requirements in Singapore
Under Singapore's PDPA framework, the agreement must address the Nine Data Protection Obligations, including consent, purpose limitation, notification, access and correction, and accuracy obligations. Both controllers must implement appropriate security arrangements to protect personal data and establish procedures for handling data subject access requests. The agreement must comply with the Personal Data Protection Regulations 2021 regarding technical and organizational measures. If data will be transferred outside Singapore, the agreement must incorporate provisions from the PDPC Advisory Guidelines on Transfer of Personal Data Outside Singapore, including adequate protection standards and transfer mechanisms. Breach notification requirements under the 2021 regulations must be clearly defined, including timelines for notifying the Personal Data Protection Commission and affected individuals when required.
GOVERNING LAW
Applicable law
This Controller To Controller DPA is drafted to comply with Singapore law. Key legislation includes:
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it