Controller Processor Agreement Template for South Africa
Generate a bespoke document
What is a Controller Processor Agreement?
This Controller Processor Agreement is essential for organizations engaging in data processing activities within or from South Africa. It is required under the Protection of Personal Information Act (POPIA) whenever a Responsible Party (Controller) engages an Operator (Processor) to process personal information on their behalf. The agreement establishes clear responsibilities, compliance obligations, and operational requirements for both parties, covering aspects such as data security, breach notification, sub-processing, and data subject rights. It is particularly crucial for demonstrating compliance with POPIA's requirements and ensuring proper governance of data processing relationships. The document should be customized based on the specific processing activities, security requirements, and operational context while maintaining compliance with South African data protection law.
About the Controller Processor Agreement
A Controller Processor Agreement is a legally binding contract that governs the relationship between a data controller (responsible party) and data processor (operator) under South African law. This agreement is mandatory under the Protection of Personal Information Act (POPIA) and establishes clear responsibilities for protecting personal information during processing activities.
When do you need this document?
You need this agreement whenever your organization engages a third-party service provider to process personal information on your behalf. This includes situations such as hiring cloud storage providers, payroll processing companies, marketing agencies handling customer data, or IT support services with access to employee information. The agreement is also required when outsourcing functions like customer service, data analytics, or any other activities involving the handling of personal information. Under POPIA, you cannot lawfully engage an operator without a written agreement that meets specific legal requirements.
Key legal considerations
The agreement must clearly define the scope and purpose of processing, ensuring that the operator only processes personal information as instructed by the responsible party. Key provisions include data security measures, breach notification procedures, restrictions on sub-processing, and requirements for returning or destroying data upon termination. The agreement should specify technical and organizational measures for protecting personal information, including access controls, encryption requirements, and staff training obligations. It must also address data subject rights, ensuring that individuals can exercise their rights under POPIA through appropriate mechanisms. Liability allocation between parties is crucial, particularly regarding potential penalties from the Information Regulator for POPIA violations.
Legal requirements in South Africa
Under POPIA, the agreement must comply with Section 22, which mandates that responsible parties ensure operators provide sufficient guarantees regarding technical and organizational security measures. The agreement must prohibit the operator from processing personal information for purposes other than those specified and require written authorization before engaging sub-processors. South African law requires that cross-border data transfers be addressed if the operator will transfer data outside the country, ensuring adequate protection levels or appropriate safeguards. The agreement must also establish procedures for cooperating with the Information Regulator during investigations and ensuring compliance with data subject access requests. Regular auditing rights and termination clauses must be included to maintain ongoing compliance with POPIA's evolving requirements and regulatory guidance.
GOVERNING LAW
Applicable law
This Controller Processor Agreement is drafted to comply with South Africa law. Key legislation includes:
Consumer Protection Act 68 of 2008: Relevant for data processing agreements when the processing involves consumer data, establishing requirements for fair and transparent processing practices
Electronic Communications and Transactions Act 25 of 2002: Governs electronic communications and transactions, including provisions relevant to data processing in electronic form and security requirements
Promotion of Access to Information Act (PAIA) 2000: Important for transparency requirements and data subject access rights that might need to be addressed in the processor agreement
Common Law Principles of Contract: South African common law principles governing contract formation, validity, and enforcement that would apply to the agreement structure
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it