Data Controller To Data Controller Agreement Template for Singapore

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Data Controller To Data Controller Agreement?

This Data Controller to Data Controller Agreement is designed for situations where two organizations need to share personal data while maintaining independent control over their respective data processing activities. The agreement is specifically structured to comply with Singapore's data protection laws, particularly the PDPA, and provides a comprehensive framework for lawful data sharing. It is essential when organizations need to establish clear boundaries of responsibility, implement appropriate security measures, and ensure compliance with Singapore's data protection requirements. The agreement covers crucial elements including data transfer mechanisms, breach notification procedures, and respective obligations of both controllers.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Singapore

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Controller To Data Controller Agreement

A Data Controller To Data Controller Agreement is a specialized legal contract that governs how two independent organizations share personal data while each maintaining control over their respective data processing activities. Under Singapore's Personal Data Protection Act (PDPA) 2012, when two organizations need to exchange personal data, they must establish clear legal frameworks to ensure compliance with data protection laws and define their respective responsibilities.

When do you need this document?

You need this agreement when your organization plans to share personal data with another independent entity for legitimate business purposes. Common scenarios include joint marketing campaigns between non-affiliated companies, sharing customer information with business partners, transferring employee data during corporate restructuring, or collaborating on research projects involving personal data. This agreement is particularly crucial when both organizations will process the shared data independently rather than one acting as a data processor for the other. Without this agreement, you risk violating Singapore's data protection laws and face potential penalties from the Personal Data Protection Commission (PDPC).

Key legal considerations

The agreement must clearly define each party's role as an independent data controller and specify the purposes for which personal data will be shared and processed. Key clauses should address data security measures, including encryption requirements and access controls, as well as data retention periods and deletion procedures. Breach notification obligations must be clearly outlined, specifying how quickly each party must inform the other and the PDPC of any security incidents. The agreement should also include provisions for cross-border data transfers if applicable, ensuring compliance with transfer limitation obligations under the PDPA. Additionally, you must address data subject rights, including how each controller will handle access requests, corrections, and withdrawal of consent from individuals whose data is shared.

Legal requirements in Singapore

Under Singapore's PDPA 2012 and Personal Data Protection Regulations 2021, both controllers must ensure they have valid consent or another lawful basis for sharing personal data. The agreement must comply with the consent obligation, purpose limitation principle, and notification requirements outlined in the Act. If the data sharing involves overseas transfers, you must implement appropriate safeguards as required by the transfer limitation obligation, which may include standard contractual clauses or adequacy decisions. Both parties must maintain records of processing activities and implement appropriate technical and organizational measures to protect personal data. The agreement should also address compliance with sector-specific regulations such as MAS Guidelines for financial institutions or healthcare regulations if applicable. Regular audits and compliance monitoring provisions should be included to ensure ongoing adherence to Singapore's evolving data protection landscape.

GOVERNING LAW

Applicable law

This Data Controller To Data Controller Agreement is drafted to comply with Singapore law. Key legislation includes:

PDPA 2012: Singapore's primary data protection legislation that governs the collection, use, disclosure, and care of personal data

Personal Data Protection Regulations 2021: Regulations providing specific requirements for overseas data transfer and data breach notification procedures

PDPC Advisory Guidelines: Official guidelines covering key PDPA concepts, data protection provisions, transfer limitation obligations, and data breach notification requirements

Industry-Specific Regulations: Sector-specific regulations such as Banking Act, MAS Guidelines, healthcare regulations, and telecoms regulations that may apply depending on the industry context

GDPR Compliance: European Union's General Data Protection Regulation considerations if EU data subjects are involved in the data processing

APEC CBPR: APEC Cross-Border Privacy Rules System framework for consistent privacy protection across APEC member economies

ASEAN Framework: ASEAN Framework on Personal Data Protection providing regional principles for data protection

Scope of Data Sharing: Agreement section defining the types of data being shared and purposes of processing

Respective Responsibilities: Agreement section outlining the specific obligations and duties of each data controller

Security Measures: Agreement section specifying the technical and organizational measures required to protect personal data

Data Breach Procedures: Agreement section detailing the protocols for handling and reporting data breaches

Cross-border Transfer Mechanisms: Agreement section describing the legal mechanisms for international data transfers

Data Subject Rights: Agreement section addressing how to handle data subject requests and rights

Liability and Indemnification: Agreement section defining the allocation of risk and responsibility between parties

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it