Data Controller To Data Controller Agreement Template for Singapore
Generate a bespoke document
What is a Data Controller To Data Controller Agreement?
This Data Controller to Data Controller Agreement is designed for situations where two organizations need to share personal data while maintaining independent control over their respective data processing activities. The agreement is specifically structured to comply with Singapore's data protection laws, particularly the PDPA, and provides a comprehensive framework for lawful data sharing. It is essential when organizations need to establish clear boundaries of responsibility, implement appropriate security measures, and ensure compliance with Singapore's data protection requirements. The agreement covers crucial elements including data transfer mechanisms, breach notification procedures, and respective obligations of both controllers.
About the Data Controller To Data Controller Agreement
A Data Controller To Data Controller Agreement is a specialized legal contract that governs how two independent organizations share personal data while each maintaining control over their respective data processing activities. Under Singapore's Personal Data Protection Act (PDPA) 2012, when two organizations need to exchange personal data, they must establish clear legal frameworks to ensure compliance with data protection laws and define their respective responsibilities.
When do you need this document?
You need this agreement when your organization plans to share personal data with another independent entity for legitimate business purposes. Common scenarios include joint marketing campaigns between non-affiliated companies, sharing customer information with business partners, transferring employee data during corporate restructuring, or collaborating on research projects involving personal data. This agreement is particularly crucial when both organizations will process the shared data independently rather than one acting as a data processor for the other. Without this agreement, you risk violating Singapore's data protection laws and face potential penalties from the Personal Data Protection Commission (PDPC).
Key legal considerations
The agreement must clearly define each party's role as an independent data controller and specify the purposes for which personal data will be shared and processed. Key clauses should address data security measures, including encryption requirements and access controls, as well as data retention periods and deletion procedures. Breach notification obligations must be clearly outlined, specifying how quickly each party must inform the other and the PDPC of any security incidents. The agreement should also include provisions for cross-border data transfers if applicable, ensuring compliance with transfer limitation obligations under the PDPA. Additionally, you must address data subject rights, including how each controller will handle access requests, corrections, and withdrawal of consent from individuals whose data is shared.
Legal requirements in Singapore
Under Singapore's PDPA 2012 and Personal Data Protection Regulations 2021, both controllers must ensure they have valid consent or another lawful basis for sharing personal data. The agreement must comply with the consent obligation, purpose limitation principle, and notification requirements outlined in the Act. If the data sharing involves overseas transfers, you must implement appropriate safeguards as required by the transfer limitation obligation, which may include standard contractual clauses or adequacy decisions. Both parties must maintain records of processing activities and implement appropriate technical and organizational measures to protect personal data. The agreement should also address compliance with sector-specific regulations such as MAS Guidelines for financial institutions or healthcare regulations if applicable. Regular audits and compliance monitoring provisions should be included to ensure ongoing adherence to Singapore's evolving data protection landscape.
GOVERNING LAW
Applicable law
This Data Controller To Data Controller Agreement is drafted to comply with Singapore law. Key legislation includes:
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it