Data Controller Agreement Template for Singapore

Generate a bespoke document

What is a Data Controller Agreement?

This Data Controller Agreement is essential when two or more organizations jointly determine the purposes and means of processing personal data in Singapore. The agreement, governed by Singapore's PDPA 2012, establishes clear responsibilities, compliance obligations, and liability allocation between joint controllers. It addresses key requirements including data protection measures, breach notification procedures, data subject rights management, and cross-border transfer protocols. This document is particularly crucial for organizations sharing data processing responsibilities while maintaining independent control over certain aspects of data processing.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Singapore

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Controller Agreement

A Data Controller Agreement is a critical legal document that governs the relationship between organizations that jointly process personal data in Singapore. Under the Personal Data Protection Act 2012 (PDPA), when two or more parties collaborate in determining how personal data is collected, used, or disclosed, they must establish clear responsibilities and compliance frameworks to protect individual privacy rights.

When do you need this document?

You need a Data Controller Agreement when your organization partners with other entities to process personal data for shared purposes. This includes joint marketing campaigns where customer databases are combined, shared customer service platforms operated by multiple companies, collaborative research projects involving personal data collection, or outsourcing arrangements where both parties retain control over data processing decisions. The agreement is also essential when establishing data-sharing partnerships with overseas entities, as it ensures compliance with Singapore's cross-border transfer requirements under the PDPA.

Key legal considerations

The agreement must clearly define each party's role as either a primary or secondary data controller, specify the scope of data processing activities, and establish mechanisms for managing data subject requests such as access, correction, or deletion. You must include detailed breach notification procedures that comply with PDPC requirements, outline data security measures that meet PDPA standards, and specify how liability will be allocated between parties in case of non-compliance. The document should also address data retention periods, deletion procedures, and protocols for handling regulatory investigations. Cross-border transfer provisions are crucial if data will be shared internationally, requiring compliance with APEC Cross-Border Privacy Rules or adequate protection standards.

Legal requirements in Singapore

Under Singapore's PDPA, joint data controllers must ensure that all Data Protection Provisions are met collectively. This includes obtaining proper consent for data collection, limiting use to specified purposes, implementing reasonable security arrangements, and providing individuals with access to their personal data. The agreement must comply with the PDPA Regulations 2021, particularly regarding mandatory breach notification to the Personal Data Protection Commission within 72 hours of discovery. You must also ensure that any cross-border transfers comply with Section 26 of the PDPA, which requires either consent or adequate protection in the receiving jurisdiction. The document should reference PDPC Advisory Guidelines and incorporate requirements for data protection impact assessments where applicable.

GOVERNING LAW

Applicable law

This Data Controller Agreement is drafted to comply with Singapore law. Key legislation includes:

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it