Data Controller Agreement Template for Singapore

Create a bespoke document in minutes,  or upload and review your own.

4.6 / 5
4.8 / 5

Let's create your Data Controller Agreement

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Get your first 2 documents free

Your data doesn't train Genie's AI

You keep IP ownership of your information

Key Requirements PROMPT example:

Data Controller Agreement

"Need a Data Controller Agreement for our Singapore-based fintech company sharing customer payment data with a third-party analytics provider, with specific emphasis on cross-border data transfers to their EU servers and breach notification procedures."

Document background
This Data Controller Agreement is essential when two or more organizations jointly determine the purposes and means of processing personal data in Singapore. The agreement, governed by Singapore's PDPA 2012, establishes clear responsibilities, compliance obligations, and liability allocation between joint controllers. It addresses key requirements including data protection measures, breach notification procedures, data subject rights management, and cross-border transfer protocols. This document is particularly crucial for organizations sharing data processing responsibilities while maintaining independent control over certain aspects of data processing.
Suggested Sections

1. Parties: Identification of the Data Controller and other contracting parties, including registration details and addresses

2. Background: Context of the agreement and relationship between parties

3. Definitions: Key terms used throughout the agreement, including PDPA-specific terminology

4. Scope and Purpose: Define the scope of data processing activities and legitimate purposes

5. Data Protection Obligations: Core obligations under PDPA including collection, use, disclosure, and protection of personal data

6. Security Measures: Technical and organizational measures for data protection

7. Breach Notification: Procedures for handling and reporting data breaches

8. Data Subject Rights: Procedures for handling data subject requests and rights

Optional Sections

1. Cross-border Transfers: Requirements and compliance measures for international data transfers outside Singapore

2. Sector-Specific Requirements: Additional requirements for regulated industries such as healthcare, finance, or telecommunications

3. Sub-processing: Terms and conditions for engaging and managing third-party data processors

4. Data Protection Impact Assessment: Requirements and procedures for conducting DPIAs for high-risk processing activities

Suggested Schedules

1. Schedule 1 - Categories of Personal Data: Detailed list of personal data types being processed under this agreement

2. Schedule 2 - Technical and Organizational Measures: Comprehensive description of security measures and controls implemented

3. Schedule 3 - Sub-processors: List of approved sub-processors, their roles, and responsibilities

4. Schedule 4 - Data Transfer Mechanisms: Details of cross-border transfer arrangements and safeguards

5. Schedule 5 - Contact Points: Key contacts for data protection matters and breach notifications

Authors

Alex Denne

Head of Growth (Open Source Law) @ Genie AI | 3 x UCL-Certified in Contract Law & Drafting | 4+ Years Managing 1M+ Legal Documents | Serial Founder & Legal AI Author

Relevant legal definitions
Clauses
Industries

Personal Data Protection Act 2012 (PDPA): Singapore's primary data protection legislation that governs the collection, use, disclosure and care of personal data. It includes Data Protection Provisions (DPP) and Do Not Call Provisions (DNC)

PDPA Regulations 2021: Updated regulations that provide specific requirements for data protection, including detailed provisions for breach notifications and enforcement mechanisms

PDPC Advisory Guidelines: Official guidelines from the Personal Data Protection Commission covering key concepts, selected topics, and data protection impact assessments

APEC Cross-Border Privacy Rules: International framework for data protection that may affect cross-border data transfers within the Asia-Pacific region

ASEAN Framework on Personal Data Protection: Regional framework providing principles for data protection within ASEAN member states

Cybersecurity Act 2018: Legislation relevant when dealing with Critical Information Infrastructure, providing cybersecurity requirements and obligations

Sector-Specific Guidelines: Specialized guidelines for different sectors including healthcare, education, telecommunications, and banking/finance, providing industry-specific data protection requirements

GDPR Compliance Considerations: While not Singapore law, relevant when dealing with EU data subjects or organizations, providing additional compliance requirements for data protection

Teams

Employer, Employee, Start Date, Job Title, Department, Location, Probationary Period, Notice Period, Salary, Overtime, Vacation Pay, Statutory Holidays, Benefits, Bonus, Expenses, Working Hours, Rest Breaks,  Leaves of Absence, Confidentiality, Intellectual Property, Non-Solicitation, Non-Competition, Code of Conduct, Termination,  Severance Pay, Governing Law, Entire Agreemen

Find the exact document you need

Personal Data Agreement

find out more

Joint Controller Data Sharing Agreement

find out more

Data Controller Agreement

find out more

Data Controller DPA

find out more

Joint Data Controller Agreement

find out more

Master Data Protection Agreement

find out more

Supplier Data Processing Agreement

find out more

Data Privacy Addendum

find out more

Non Disclosure Agreement Data Protection

find out more

Download our whitepaper on the future of AI in Legal

By providing your email address you are consenting to our Privacy Notice.
Thank you for downloading our whitepaper. This should arrive in your inbox shortly. In the meantime, why not jump straight to a section that interests you here: https://www.genieai.co/our-research
Oops! Something went wrong while submitting the form.

Genie’s Security Promise

Genie is the safest place to draft. Here’s how we prioritise your privacy and security.

Your documents are private:

We do not train on your data; Genie’s AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

Our bank-grade security infrastructure undergoes regular external audits

We are ISO27001 certified, so your data is secure

Organizational security

You retain IP ownership of your documents

You have full control over your data and who gets to see it

Innovation in privacy:

Genie partnered with the Computational Privacy Department at Imperial College London

Together, we ran a £1 million research project on privacy and anonymity in legal contracts

Want to know more?

Visit our Trust Centre for more details and real-time security updates.