Data Controller To Data Controller Agreement Template for South Africa

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Data Controller To Data Controller Agreement?

The Data Controller to Data Controller Agreement is essential when two organizations need to share personal information while acting as independent controllers under South African law. This document is required whenever organizations jointly process or exchange personal information, ensuring compliance with the Protection of Personal Information Act (POPIA). The agreement details each party's obligations, data protection responsibilities, security requirements, and procedures for managing data subject rights. It is particularly crucial in scenarios where organizations regularly share customer, employee, or other personal information databases, conduct joint ventures, or participate in data-sharing initiatives. The document includes specific provisions required by South African law, including Information Regulator notification requirements and local data protection standards.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

South Africa

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Controller To Data Controller Agreement

When two organizations need to share personal information while maintaining their independence as data controllers, you need a Data Controller to Data Controller Agreement that complies with South African law. This legal document establishes the framework for lawful data sharing between entities that process personal information for their own purposes, ensuring compliance with the Protection of Personal Information Act (POPIA) and protecting both organizations from regulatory penalties.

When do you need this document?

You need this agreement whenever your organization plans to share personal information with another entity that will use the data for its own business purposes. This includes scenarios where companies exchange customer databases for marketing purposes, share employee information during corporate restructuring, or collaborate on joint ventures involving personal data processing. The agreement is also essential when organizations participate in industry data-sharing initiatives, conduct joint research involving personal information, or merge customer databases following business partnerships. Under POPIA, any transfer of personal information between independent controllers requires proper legal documentation to ensure lawful processing and protect data subjects' rights.

Key legal considerations

Your agreement must clearly define each party's role as an independent data controller and specify the lawful basis for data processing under POPIA. Include detailed provisions covering data security measures, breach notification procedures, and protocols for handling data subject requests such as access, correction, or deletion. The document should establish liability frameworks, indemnification clauses, and procedures for managing regulatory investigations. Consider including data retention periods, deletion requirements, and specific technical and organizational security measures that both parties must implement. Address cross-border transfer restrictions if data will be shared internationally, ensuring compliance with POPIA's transborder information flow requirements.

Legal requirements in South Africa

Under South African law, your Data Controller to Data Controller Agreement must comply with POPIA's eight data protection principles, including accountability, processing limitation, and security safeguards. Both parties must be registered with the Information Regulator of South Africa if required by their processing activities. The agreement should reference Section 14 of the Constitution, which establishes the fundamental right to privacy, and ensure alignment with the Electronic Communications and Transactions Act for electronic data transfers. Include provisions for notifying the Information Regulator of data breaches within 72 hours as required by POPIA regulations. The document must also address data subject consent requirements, specify procedures for obtaining and managing consent, and establish mechanisms for data subjects to exercise their rights under POPIA. Consider Consumer Protection Act implications if the shared data involves consumer information, ensuring additional protections are in place.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it