Joint Data Controller Agreement Template for Singapore

Generate a bespoke document

What is a Joint Data Controller Agreement?

The Joint Data Controller Agreement is essential when two or more organizations jointly determine the purposes and means of processing personal data in Singapore. This agreement ensures compliance with the Personal Data Protection Act 2012 and related regulations while clearly defining each party's obligations and responsibilities. It addresses key aspects such as data protection measures, breach notification procedures, data subject rights management, and liability allocation between controllers. This document is particularly crucial for organizations engaging in collaborative data processing activities where both parties have significant control over how personal data is handled.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Singapore

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Joint Data Controller Agreement

A Joint Data Controller Agreement is a crucial legal document that governs the relationship between two or more organizations when they jointly determine the purposes and means of processing personal data in Singapore. Under the Personal Data Protection Act 2012 (PDPA), when multiple entities share control over data processing decisions, they must establish clear frameworks for compliance, responsibility allocation, and data subject protection.

When do you need this document?

You need a Joint Data Controller Agreement when your organization collaborates with other entities in processing personal data where both parties have meaningful input into how and why the data is processed. This includes joint marketing campaigns where multiple companies share customer databases, research partnerships involving shared participant data, or collaborative platforms where multiple organizations contribute to data processing decisions. The agreement is also essential when establishing joint ventures that involve personal data processing, or when multiple subsidiaries under different legal entities need to process data collectively. Without this agreement, you risk regulatory non-compliance and unclear liability exposure under Singapore's data protection framework.

Key legal considerations

The agreement must clearly define each party's roles and responsibilities under the PDPA, including who handles data subject access requests, breach notifications, and consent management. You need to establish liability allocation mechanisms that specify which party bears responsibility for different types of compliance failures or data breaches. The document should include detailed data processing purposes, lawful bases for processing, and retention periods that comply with PDPA requirements. Security obligations must be clearly specified, including technical and organizational measures each party must implement. The agreement should also address data transfer arrangements, particularly if data crosses borders, and establish procedures for handling data subject rights including access, correction, and deletion requests.

Legal requirements in Singapore

Under Singapore's PDPA 2012 and its 2020 amendments, joint data controllers must ensure compliance with all data protection obligations, including obtaining valid consent where required and implementing appropriate security measures. The agreement must align with PDPA Key Concepts Guidelines and Selected Topics Guidelines issued by the Personal Data Protection Commission. You must establish clear accountability frameworks that satisfy regulatory expectations for data governance and risk management. The document should incorporate requirements for Data Protection Impact Assessments (DPIA) where high-risk processing is involved, following the DPIA Guidelines. Additionally, the agreement must consider regional compliance requirements under the ASEAN Framework on Personal Data Protection and ensure alignment with cross-border data transfer restrictions under Singapore law.

GOVERNING LAW

Applicable law

This Joint Data Controller Agreement is drafted to comply with Singapore law. Key legislation includes:

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it