Joint Controller Data Sharing Agreement Template for Singapore

Generate a bespoke document

What is a Joint Controller Data Sharing Agreement?

The Joint Controller Data Sharing Agreement is essential when two or more organizations jointly determine how personal data will be processed. This agreement, governed by Singapore law and the PDPA, establishes clear responsibilities and obligations for each controller, ensuring compliant data processing. It addresses key aspects such as data security, breach notification, data subject rights, and cross-border transfers. The agreement is particularly important in today's interconnected business environment where data sharing is increasingly common and regulatory scrutiny is heightening.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Singapore

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Joint Controller Data Sharing Agreement

When multiple organizations work together to process personal data, you need a Joint Controller Data Sharing Agreement to establish clear legal responsibilities under Singapore's Personal Data Protection Act 2012. This agreement defines how each party will handle shared personal data while ensuring compliance with PDPA requirements and protecting both organizations from regulatory risks.

When do you need this document?

You require this agreement when your organization jointly determines the purposes and means of processing personal data with another entity. Common scenarios include healthcare providers sharing patient information for treatment coordination, financial institutions collaborating on customer verification, government agencies exchanging citizen data for public services, or companies partnering on marketing campaigns using shared customer databases. The agreement is mandatory under PDPA when both parties have decision-making authority over the data processing activities, rather than one acting as a mere data processor for the other.

Key legal considerations

Your agreement must clearly define each controller's specific responsibilities under the PDPA's Data Protection Provisions. Critical clauses include data security measures that meet PDPA standards, procedures for handling data subject access requests and complaints, breach notification protocols that comply with the Personal Data Protection Regulations 2021, and mechanisms for ensuring lawful basis for processing. You should address data retention periods, deletion procedures, and audit rights to maintain ongoing compliance. The agreement must also specify how you'll handle conflicts between controllers and establish dispute resolution mechanisms. Transfer limitation obligations become crucial if data will be shared across borders, requiring additional safeguards under PDPA.

Legal requirements in Singapore

Under Singapore law, your Joint Controller Data Sharing Agreement must comply with the Personal Data Protection Act 2012 and associated regulations. Each controller remains individually liable for PDPA compliance, meaning you cannot simply delegate responsibility to your partner. The agreement must address the PDPA's consent requirements, ensuring you have appropriate legal basis for sharing personal data. You must implement the Advisory Guidelines on Key Concepts in the PDPA, particularly regarding purpose limitation and data minimization principles. If your arrangement involves ICT systems, incorporate the Guidelines on Data Protection by Design for ICT Systems to ensure technical compliance. The Personal Data Protection Commission expects clear accountability frameworks, so your agreement should demonstrate how both parties will meet their obligations under the Data Protection Provisions while maintaining individual responsibility for regulatory compliance.

GOVERNING LAW

Applicable law

This Joint Controller Data Sharing Agreement is drafted to comply with Singapore law. Key legislation includes:

Personal Data Protection Act 2012 (PDPA): Singapore's primary data protection legislation that governs the collection, use, disclosure, and care of personal data. Contains key Data Protection Provisions that form the backbone of data protection requirements.

Personal Data Protection Regulations 2021: Supplementary regulations that provide detailed requirements for data protection, including transfer limitation obligations and data breach notification requirements.

Advisory Guidelines on Key Concepts in the PDPA: Official guidelines issued by the Personal Data Protection Commission (PDPC) providing interpretation and practical guidance on PDPA requirements.

Guidelines on Data Protection by Design for ICT Systems: Technical guidelines focusing on implementing data protection measures in information and communication technology systems.

Guide to Data Sharing: Specific PDPC guidance document providing detailed recommendations and requirements for data sharing arrangements between organizations.

Transfer Limitation Obligation: Specific provisions under PDPA governing the transfer of personal data outside of Singapore, including requirements for ensuring comparable protection standards.

APEC Cross-Border Privacy Rules (CBPR) System: International framework for data protection that may need to be considered for cross-border data transfers within APEC member economies.

ASEAN Framework on Personal Data Protection: Regional framework providing principles for data protection within ASEAN member states, relevant for regional data sharing considerations.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it