Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
DPA Agreement
"I need a DPA Agreement for my UAE-based healthcare technology company acting as a data controller, engaging a cloud service provider to process patient data, with specific provisions for handling sensitive medical information and cross-border data transfers to EU-based servers."
1. Parties: Identification of the data controller and data processor, including full legal names and registration details
2. Background: Context of the agreement, relationship between parties, and purpose of data processing activities
3. Definitions: Definitions of key terms used in the agreement, aligned with UAE Federal Decree-Law No. 45/2021
4. Scope and Purpose of Processing: Detailed description of the permitted data processing activities and their specific purposes
5. Duration of Processing: Timeline for data processing activities and conditions for termination
6. Nature and Categories of Personal Data: Specification of personal data types to be processed and categories of data subjects
7. Obligations of the Data Processor: Comprehensive list of processor's responsibilities including security, confidentiality, and compliance measures
8. Obligations of the Data Controller: Controller's responsibilities, including lawful basis for processing and instructions to processor
9. Data Subject Rights: Procedures for handling data subject requests and ensuring compliance with UAE data protection laws
10. Data Security Measures: Required technical and organizational security measures to protect personal data
11. Breach Notification: Procedures and timeframes for reporting and handling data breaches
12. Audit Rights: Controller's rights to audit processor's compliance and processor's obligations to demonstrate compliance
13. Liability and Indemnification: Allocation of liability and indemnification obligations between parties
14. Termination: Conditions for termination and obligations regarding data return or deletion
15. Governing Law and Jurisdiction: Specification of UAE law as governing law and jurisdiction for disputes
1. Cross-border Data Transfers: Required when personal data will be transferred outside the UAE, including mechanisms for ensuring adequate protection
2. Sub-processors: Include when the processor may engage sub-processors, specifying requirements for appointment and oversight
3. Special Categories of Personal Data: Required when processing sensitive personal data, including additional safeguards
4. Data Protection Impact Assessment: Include when high-risk processing activities require DPIA under UAE law
5. Industry-Specific Requirements: Add when processing involves regulated sectors (e.g., healthcare, financial services)
6. Data Localization Requirements: Include when specific data must be stored within UAE territory
7. Insurance Requirements: Include when specific insurance coverage for data processing activities is required
1. Schedule 1: Processing Activities: Detailed description of specific processing activities, including purposes, categories of data, and processing operations
2. Schedule 2: Technical and Organizational Measures: Detailed security measures and controls implemented to protect personal data
3. Schedule 3: Approved Sub-processors: List of approved sub-processors and their processing activities, if applicable
4. Schedule 4: Data Transfer Mechanisms: Details of mechanisms used for international data transfers, including any standard contractual clauses
5. Schedule 5: Contact Details: Contact information for key personnel, including data protection officers and emergency contacts
6. Appendix A: Security Breach Response Plan: Detailed procedures for handling and reporting data breaches
7. Appendix B: Data Subject Request Procedures: Procedures for handling data subject rights requests
Authors
Applicable Law
Authorized Person
Confidential Information
Data Controller
Data Processor
Data Protection Law
Data Subject
Data Subject Request
Executive Regulations
Personal Data
Personal Data Breach
Processing
Processing Instructions
Processing Records
Regulatory Authority
Security Measures
Sensitive Personal Data
Services
Sub-processor
Technical Measures
Organizational Measures
Transfer Mechanism
UAE
Cross-border Transfer
Data Protection Impact Assessment
Data Protection Officer
Processing Location
Security Standards
Supervisory Authority
Scope
Data Protection
Processing Requirements
Confidentiality
Security
Audit Rights
Breach Notification
Sub-processing
Data Transfer
Compliance
Liability
Indemnification
Insurance
Term and Termination
Assignment
Force Majeure
Notices
Severability
Entire Agreement
Amendment
Waiver
Governing Law
Dispute Resolution
Data Subject Rights
Record Keeping
Cooperation
Technology
Healthcare
Financial Services
E-commerce
Telecommunications
Education
Professional Services
Real Estate
Hospitality
Retail
Manufacturing
Insurance
Transportation
Energy
Media and Entertainment
Legal
Compliance
Information Security
IT
Privacy
Risk Management
Procurement
Operations
Data Governance
Vendor Management
Information Technology
Corporate Affairs
Chief Privacy Officer
Data Protection Officer
Chief Information Security Officer
Legal Counsel
Compliance Manager
IT Director
Risk Manager
Information Security Manager
Privacy Manager
Operations Director
Procurement Manager
Vendor Management Officer
Chief Technology Officer
Chief Legal Officer
Data Governance Manager
Find the exact document you need
Joint Controller Agreement
A UAE law-compliant agreement establishing responsibilities and obligations between parties jointly controlling personal data processing activities.
Data Processing Addendum
A UAE law-compliant agreement establishing terms for personal data processing between controllers and processors under Federal Decree Law No. 45 of 2021.
Data Sharing Agreement Controller To Processor
UAE-law governed agreement establishing terms for processing personal data between a Controller and Processor, compliant with Federal Decree-Law No. 45/2021.
Controller To Controller Data Processing Agreement
UAE-law governed agreement establishing data sharing arrangements between two independent data controllers, compliant with Federal Decree Law No. 45 of 2021.
Intercompany Data Processing Agreement
UAE-law governed agreement regulating personal data processing between affiliated companies, ensuring compliance with UAE Federal Decree Law No. 45 of 2021.
Controller To Controller DPA
UAE-governed Controller to Controller DPA establishing framework for personal data sharing between independent controllers under Federal Decree-Law No. 45/2021.
DPA Agreement
UAE-compliant Data Processing Agreement establishing terms for personal data processing between controller and processor under Federal Decree-Law No. 45/2021.
Third Party Data Processing Agreement
UAE-law governed agreement regulating personal data processing activities between a controller and processor, compliant with Federal Decree Law No. 45 of 2021.
Personal Data Transfer Agreement
UAE-compliant agreement template for cross-border personal data transfers, aligned with Federal Decree-Law No. 45/2021 and free zone regulations.
Controller Processor Agreement
A UAE-compliant agreement governing data processing activities between controllers and processors under Federal Decree-Law No. 45/2021.
Affiliate Addendum
UAE-governed addendum defining affiliate marketing relationships, commission structures, and compliance requirements under UAE law.
Data Privacy Addendum
A legal addendum ensuring compliance with UAE data protection laws and regulations, establishing data processing rights and obligations between parties.
Sub Processing Agreement
UAE-governed Sub Processing Agreement establishing terms for outsourced data processing activities in compliance with UAE Federal Decree Law No. 45 of 2021.
International Data Transfer Agreement
UAE-compliant International Data Transfer Agreement governing cross-border personal data transfers under Federal Decree-Law No. 45/2021.
Data Protection Addendum
A legal addendum ensuring compliance with UAE federal and free zone data protection laws, establishing data processing rights and obligations between parties.
Download our whitepaper on the future of AI in Legal
Genie’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; Genie’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our Trust Centre for more details and real-time security updates.
Read our Privacy Policy.