Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Data Sharing Agreement Controller To Processor
"I need a Data Sharing Agreement Controller To Processor for my UAE-based healthcare technology company to engage a cloud service provider who will process our patients' medical records, with specific provisions for data localization within the UAE and enhanced security measures for sensitive health data."
1. Parties: Identification of the Data Controller and Data Processor, including full legal names, registration details, and addresses
2. Background: Context of the data sharing arrangement, relationship between parties, and purpose of the agreement
3. Definitions: Definitions of key terms used in the agreement, aligned with UAE Federal Decree-Law No. 45/2021 terminology
4. Scope and Purpose of Processing: Detailed description of the data processing activities, categories of data, and purposes of processing
5. Duration of Processing: Term of the agreement and processing activities, including renewal provisions
6. Obligations of the Data Controller: Controller's responsibilities, including lawful basis for processing, instructions to processor, and oversight duties
7. Obligations of the Data Processor: Processor's duties including processing only on documented instructions, confidentiality, security measures, and subprocessing restrictions
8. Data Security Measures: Technical and organizational security measures required under UAE law and industry standards
9. Data Subject Rights: Procedures for handling data subject requests and processor's assistance obligations
10. Personal Data Breach Management: Breach notification procedures, response protocols, and cooperation requirements
11. Audit Rights and Compliance: Controller's audit rights and processor's compliance demonstration obligations
12. Liability and Indemnification: Allocation of liability and indemnification obligations between parties
13. Termination: Termination circumstances, notice periods, and data deletion/return obligations
14. Governing Law and Jurisdiction: Specification of UAE law as governing law and jurisdiction for disputes
1. Cross-border Data Transfers: Required when personal data will be transferred outside the UAE, including mechanisms for ensuring adequate protection
2. Industry-Specific Requirements: Include when processing data in regulated sectors like healthcare or financial services
3. Data Protection Impact Assessment: Required when processing activities are likely to result in high risk to individuals
4. Insurance Requirements: Specific insurance obligations for high-risk processing activities
5. Force Majeure: Provisions for handling unforeseen circumstances affecting data processing activities
6. Change Control: Procedures for managing changes to processing activities or security measures
7. Dispute Resolution: Alternative dispute resolution procedures before court proceedings
1. Schedule 1 - Processing Activities: Detailed description of processing activities, including data categories, purposes, and processing operations
2. Schedule 2 - Technical and Organizational Measures: Detailed security measures and controls implemented by the Processor
3. Schedule 3 - Authorized Sub-processors: List of approved sub-processors and their processing activities
4. Schedule 4 - Data Transfer Mechanisms: Details of cross-border transfer mechanisms and safeguards if applicable
5. Schedule 5 - Service Levels: Performance metrics and service levels for processing activities
6. Appendix A - Data Breach Response Plan: Detailed procedures for handling and reporting data breaches
7. Appendix B - Data Subject Request Procedures: Procedures for handling data subject rights requests
Authors
Applicable Law
Authorized Person
Confidential Information
Controller
Cross Border Transfer
Data Protection Law
Data Subject
Data Subject Request
Executive Regulations
Personal Data
Personal Data Breach
Processing
Processor
Processing Instructions
Processing Records
Security Measures
Services
Sensitive Personal Data
Sub-processor
Technical Measures
Organizational Measures
Term
Third Party
Transfer Mechanism
UAE
Working Day
Interpretation
Scope
Duration
Processing Requirements
Data Protection
Confidentiality
Security
Sub-Processing
Audit Rights
Data Subject Rights
Data Breach
Cross-Border Transfers
Warranties
Indemnification
Liability
Insurance
Force Majeure
Assignment
Severability
Variation
Notices
Waiver
Entire Agreement
Third Party Rights
Dispute Resolution
Governing Law
Jurisdiction
Technology
Healthcare
Financial Services
E-commerce
Education
Telecommunications
Professional Services
Real Estate
Hospitality
Manufacturing
Retail
Insurance
Transportation and Logistics
Legal
Compliance
Information Security
IT
Privacy
Risk Management
Procurement
Operations
Data Governance
Information Management
Vendor Management
Chief Privacy Officer
Data Protection Officer
Chief Information Security Officer
Legal Counsel
Compliance Manager
IT Director
Privacy Manager
Risk Manager
Information Security Manager
Operations Director
Procurement Manager
Contract Manager
Chief Technology Officer
Chief Legal Officer
Chief Compliance Officer
Find the exact document you need
Joint Controller Agreement
A UAE law-compliant agreement establishing responsibilities and obligations between parties jointly controlling personal data processing activities.
Data Processing Addendum
A UAE law-compliant agreement establishing terms for personal data processing between controllers and processors under Federal Decree Law No. 45 of 2021.
Data Sharing Agreement Controller To Processor
UAE-law governed agreement establishing terms for processing personal data between a Controller and Processor, compliant with Federal Decree-Law No. 45/2021.
Controller To Controller Data Processing Agreement
UAE-law governed agreement establishing data sharing arrangements between two independent data controllers, compliant with Federal Decree Law No. 45 of 2021.
Intercompany Data Processing Agreement
UAE-law governed agreement regulating personal data processing between affiliated companies, ensuring compliance with UAE Federal Decree Law No. 45 of 2021.
Controller To Controller DPA
UAE-governed Controller to Controller DPA establishing framework for personal data sharing between independent controllers under Federal Decree-Law No. 45/2021.
DPA Agreement
UAE-compliant Data Processing Agreement establishing terms for personal data processing between controller and processor under Federal Decree-Law No. 45/2021.
Third Party Data Processing Agreement
UAE-law governed agreement regulating personal data processing activities between a controller and processor, compliant with Federal Decree Law No. 45 of 2021.
Personal Data Transfer Agreement
UAE-compliant agreement template for cross-border personal data transfers, aligned with Federal Decree-Law No. 45/2021 and free zone regulations.
Controller Processor Agreement
A UAE-compliant agreement governing data processing activities between controllers and processors under Federal Decree-Law No. 45/2021.
Affiliate Addendum
UAE-governed addendum defining affiliate marketing relationships, commission structures, and compliance requirements under UAE law.
Data Privacy Addendum
A legal addendum ensuring compliance with UAE data protection laws and regulations, establishing data processing rights and obligations between parties.
Sub Processing Agreement
UAE-governed Sub Processing Agreement establishing terms for outsourced data processing activities in compliance with UAE Federal Decree Law No. 45 of 2021.
International Data Transfer Agreement
UAE-compliant International Data Transfer Agreement governing cross-border personal data transfers under Federal Decree-Law No. 45/2021.
Data Protection Addendum
A legal addendum ensuring compliance with UAE federal and free zone data protection laws, establishing data processing rights and obligations between parties.
Download our whitepaper on the future of AI in Legal
Genie’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; Genie’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our Trust Centre for more details and real-time security updates.
Read our Privacy Policy.