Controller Processor Agreement Template for South Africa

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Controller Processor Agreement?

This Controller Processor Agreement is essential for organizations engaging in data processing activities within or from South Africa. It is required under the Protection of Personal Information Act (POPIA) whenever a Responsible Party (Controller) engages an Operator (Processor) to process personal information on their behalf. The agreement establishes clear responsibilities, compliance obligations, and operational requirements for both parties, covering aspects such as data security, breach notification, sub-processing, and data subject rights. It is particularly crucial for demonstrating compliance with POPIA's requirements and ensuring proper governance of data processing relationships. The document should be customized based on the specific processing activities, security requirements, and operational context while maintaining compliance with South African data protection law.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

South Africa

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Controller Processor Agreement

A Controller Processor Agreement is a legally binding contract that governs the relationship between a data controller (responsible party) and data processor (operator) under South African law. This agreement is mandatory under the Protection of Personal Information Act (POPIA) and establishes clear responsibilities for protecting personal information during processing activities.

When do you need this document?

You need this agreement whenever your organization engages a third-party service provider to process personal information on your behalf. This includes situations such as hiring cloud storage providers, payroll processing companies, marketing agencies handling customer data, or IT support services with access to employee information. The agreement is also required when outsourcing functions like customer service, data analytics, or any other activities involving the handling of personal information. Under POPIA, you cannot lawfully engage an operator without a written agreement that meets specific legal requirements.

Key legal considerations

The agreement must clearly define the scope and purpose of processing, ensuring that the operator only processes personal information as instructed by the responsible party. Key provisions include data security measures, breach notification procedures, restrictions on sub-processing, and requirements for returning or destroying data upon termination. The agreement should specify technical and organizational measures for protecting personal information, including access controls, encryption requirements, and staff training obligations. It must also address data subject rights, ensuring that individuals can exercise their rights under POPIA through appropriate mechanisms. Liability allocation between parties is crucial, particularly regarding potential penalties from the Information Regulator for POPIA violations.

Legal requirements in South Africa

Under POPIA, the agreement must comply with Section 22, which mandates that responsible parties ensure operators provide sufficient guarantees regarding technical and organizational security measures. The agreement must prohibit the operator from processing personal information for purposes other than those specified and require written authorization before engaging sub-processors. South African law requires that cross-border data transfers be addressed if the operator will transfer data outside the country, ensuring adequate protection levels or appropriate safeguards. The agreement must also establish procedures for cooperating with the Information Regulator during investigations and ensuring compliance with data subject access requests. Regular auditing rights and termination clauses must be included to maintain ongoing compliance with POPIA's evolving requirements and regulatory guidance.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it