Data Controller DPA Template for Singapore
Generate a bespoke document
What is a Data Controller DPA?
The Data Controller DPA is essential when an organization (controller) engages another party (processor) to process personal data on its behalf in Singapore. This agreement is required under the Personal Data Protection Act 2012 (PDPA) to ensure proper data handling, security measures, and compliance with Singapore's data protection regulations. The document outlines specific responsibilities, including data security measures, breach notification procedures, cross-border transfer requirements, and sub-processor arrangements. It's particularly crucial for organizations handling sensitive personal data or engaging in complex data processing activities.
Trusted by high-performance teams
About the Data Controller DPA
A Data Controller DPA is a legally binding agreement that governs the relationship between organizations when one party processes personal data on behalf of another under Singapore's data protection framework. This contract is essential for maintaining compliance with the Personal Data Protection Act 2012 and ensuring that both parties understand their respective obligations when handling personal data.
When do you need this document?
You need a Data Controller DPA whenever your organization engages a third-party service provider to process personal data on your behalf. This includes situations where you outsource customer service operations, engage cloud storage providers, hire payroll processing companies, or work with marketing agencies that handle customer data. The agreement is also required when engaging IT support services that access employee data, using third-party analytics platforms, or partnering with logistics companies that handle customer delivery information. Singapore's PDPA makes this agreement mandatory for any data processing relationship where you remain responsible for the data while another party performs the actual processing activities.
Key legal considerations
The agreement must clearly define the roles of data controller and data processor, with the controller retaining ultimate responsibility for PDPA compliance. Key clauses should address the purpose and scope of data processing, ensuring that processors only handle data as specifically instructed and for authorized purposes. Security measures must meet PDPA standards, including technical and organizational safeguards to protect personal data from unauthorized access, disclosure, or destruction. The contract should establish clear procedures for handling data subject requests, including access, correction, and deletion requests that must be processed within PDPA timeframes. Data breach notification requirements are critical, with processors obligated to notify controllers immediately upon discovering any security incidents. Cross-border transfer provisions must comply with PDPA requirements, particularly when data is transferred outside Singapore to jurisdictions without adequate protection levels.
Legal requirements in Singapore
Under the PDPA 2012, data controllers must ensure that processors provide sufficient guarantees regarding technical and organizational security measures. The agreement must include specific provisions addressing the nine main PDPA obligations, including consent management, purpose limitation, notification requirements, and access and correction procedures. Processors must implement appropriate security arrangements as outlined in the Data Protection Provisions and maintain detailed records of processing activities. The contract must address sub-processor arrangements, requiring controllers to provide explicit authorization before processors engage additional third parties. Data retention and deletion requirements must be clearly specified, ensuring personal data is destroyed or returned upon contract termination. The agreement should also incorporate requirements from the PDPA Regulations 2021 and Data Breach Regulations 2021, including mandatory breach notification procedures and timelines for reporting incidents to both controllers and the Personal Data Protection Commission.
GOVERNING LAW
Applicable law
This Data Controller DPA is drafted to comply with Singapore law. Key legislation includes:
DPIA Guidelines: Guide to conducting Data Protection Impact Assessments in Singapore
Cross-border Transfers: Requirements for transferring personal data outside of Singapore
Data Subject Rights: Individual rights including access, correction, and data portability
Security Measures: Technical and organizational measures required to protect personal data
Retention Limitations: Requirements for limiting retention of personal data and secure disposal
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

