Data Controller To Data Controller Agreement Template for South Africa
Generate a bespoke document
What is a Data Controller To Data Controller Agreement?
The Data Controller to Data Controller Agreement is essential when two organizations need to share personal information while acting as independent controllers under South African law. This document is required whenever organizations jointly process or exchange personal information, ensuring compliance with the Protection of Personal Information Act (POPIA). The agreement details each party's obligations, data protection responsibilities, security requirements, and procedures for managing data subject rights. It is particularly crucial in scenarios where organizations regularly share customer, employee, or other personal information databases, conduct joint ventures, or participate in data-sharing initiatives. The document includes specific provisions required by South African law, including Information Regulator notification requirements and local data protection standards.
About the Data Controller To Data Controller Agreement
When two organizations need to share personal information while maintaining their independence as data controllers, you need a Data Controller to Data Controller Agreement that complies with South African law. This legal document establishes the framework for lawful data sharing between entities that process personal information for their own purposes, ensuring compliance with the Protection of Personal Information Act (POPIA) and protecting both organizations from regulatory penalties.
When do you need this document?
You need this agreement whenever your organization plans to share personal information with another entity that will use the data for its own business purposes. This includes scenarios where companies exchange customer databases for marketing purposes, share employee information during corporate restructuring, or collaborate on joint ventures involving personal data processing. The agreement is also essential when organizations participate in industry data-sharing initiatives, conduct joint research involving personal information, or merge customer databases following business partnerships. Under POPIA, any transfer of personal information between independent controllers requires proper legal documentation to ensure lawful processing and protect data subjects' rights.
Key legal considerations
Your agreement must clearly define each party's role as an independent data controller and specify the lawful basis for data processing under POPIA. Include detailed provisions covering data security measures, breach notification procedures, and protocols for handling data subject requests such as access, correction, or deletion. The document should establish liability frameworks, indemnification clauses, and procedures for managing regulatory investigations. Consider including data retention periods, deletion requirements, and specific technical and organizational security measures that both parties must implement. Address cross-border transfer restrictions if data will be shared internationally, ensuring compliance with POPIA's transborder information flow requirements.
Legal requirements in South Africa
Under South African law, your Data Controller to Data Controller Agreement must comply with POPIA's eight data protection principles, including accountability, processing limitation, and security safeguards. Both parties must be registered with the Information Regulator of South Africa if required by their processing activities. The agreement should reference Section 14 of the Constitution, which establishes the fundamental right to privacy, and ensure alignment with the Electronic Communications and Transactions Act for electronic data transfers. Include provisions for notifying the Information Regulator of data breaches within 72 hours as required by POPIA regulations. The document must also address data subject consent requirements, specify procedures for obtaining and managing consent, and establish mechanisms for data subjects to exercise their rights under POPIA. Consider Consumer Protection Act implications if the shared data involves consumer information, ensuring additional protections are in place.
GOVERNING LAW
Applicable law
This Data Controller To Data Controller Agreement is drafted to comply with South Africa law. Key legislation includes:
Electronic Communications and Transactions Act 25 of 2002: Governs electronic communications and transactions, including requirements for electronic signatures and the legal recognition of electronic documents
Constitution of the Republic of South Africa, 1996: Section 14 establishes the fundamental right to privacy, which underlies data protection legislation
Consumer Protection Act 68 of 2008: May be relevant if the data subjects are consumers, as it provides additional protection regarding the collection and use of personal information in commercial contexts
Promotion of Access to Information Act (PAIA) 2 of 2000: Governs access to information held by public and private bodies, which may be relevant for data subject access requests and transparency obligations
Common Law of Contract: General principles of contract law that govern the formation and enforcement of the agreement between the data controllers
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it