Controller To Controller DPA Template for Singapore

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Controller To Controller DPA?

The Controller to Controller DPA is essential when two organizations acting as independent data controllers need to share personal data in Singapore. This agreement type is particularly important under Singapore's PDPA framework, which requires organizations to implement appropriate data protection measures when handling personal data. The document outlines specific responsibilities, security requirements, breach notification procedures, and compliance obligations for both controllers, ensuring lawful and secure data sharing practices while maintaining individual privacy rights.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Singapore

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Controller To Controller DPA

A Controller To Controller Data Protection Agreement (DPA) is a legal contract between two organizations that both act as independent data controllers under Singapore's Personal Data Protection Act 2012 (PDPA). This agreement establishes the terms and conditions for sharing personal data between the parties while ensuring compliance with Singapore's data protection framework and maintaining the privacy rights of individuals whose data is being processed.

When do you need this document?

You need a Controller To Controller DPA when your organization plans to share personal data with another company that will use that data for its own independent purposes. Common scenarios include business partnerships where customer lists are shared, joint marketing initiatives between companies, mergers and acquisitions involving data transfer, or collaborative research projects. Under the PDPA, both organizations remain independently responsible for their data processing activities, making this agreement essential for defining respective obligations and ensuring regulatory compliance.

Key legal considerations

The agreement must clearly define the scope and purpose of data sharing, ensuring both parties understand their roles as independent data controllers. Critical clauses include data security measures that meet PDPA standards, breach notification procedures that comply with the Personal Data Protection (Notification of Data Breaches) Regulations 2021, and provisions for international data transfers if applicable. The document should specify retention periods, data minimization principles, and individual rights management procedures. Both parties must ensure they have appropriate consent or legitimate grounds for processing under the PDPA's consent framework or other lawful bases for processing.

Legal requirements in Singapore

Under Singapore's PDPA framework, the agreement must address the Nine Data Protection Obligations, including consent, purpose limitation, notification, access and correction, and accuracy obligations. Both controllers must implement appropriate security arrangements to protect personal data and establish procedures for handling data subject access requests. The agreement must comply with the Personal Data Protection Regulations 2021 regarding technical and organizational measures. If data will be transferred outside Singapore, the agreement must incorporate provisions from the PDPC Advisory Guidelines on Transfer of Personal Data Outside Singapore, including adequate protection standards and transfer mechanisms. Breach notification requirements under the 2021 regulations must be clearly defined, including timelines for notifying the Personal Data Protection Commission and affected individuals when required.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it