Commissioned Data Processing Agreement Template for the Netherlands

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Commissioned Data Processing Agreement?

A Commissioned Data Processing Agreement is required under Article 28 GDPR whenever an organization (controller) engages another party (processor) to process personal data on its behalf. This document, governed by Dutch law, establishes the mandatory framework for such processing activities, ensuring compliance with both GDPR and Dutch data protection requirements. It details the processor's obligations, security measures, data handling procedures, and compliance mechanisms. The agreement is essential for Dutch businesses and international organizations processing personal data in the Netherlands, as it incorporates specific requirements from the Dutch GDPR Implementation Act (UAVG) and guidance from the Dutch Data Protection Authority. The Commissioned Data Processing Agreement should be put in place before any processing activities commence and should be regularly reviewed to ensure continued compliance with evolving data protection standards.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Netherlands

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Commissioned Data Processing Agreement

A Commissioned Data Processing Agreement is a legally mandatory contract that governs the relationship between data controllers and data processors under Netherlands law. When your organization engages a third party to handle personal data on your behalf, Article 28 of the GDPR requires a comprehensive written agreement that establishes clear responsibilities, security obligations, and compliance mechanisms.

When do you need this document?

You must have a Commissioned Data Processing Agreement in place whenever you engage external service providers to process personal data. This includes scenarios such as hiring cloud storage providers, payroll processors, marketing agencies handling customer data, or IT support companies accessing employee information. The agreement is required before any processing activities begin and applies to both Dutch companies and international organizations processing personal data within the Netherlands. Even seemingly simple services like email hosting or customer relationship management systems require this legal framework.

Key legal considerations

The agreement must specify the subject matter, duration, nature, and purpose of processing, along with the categories of personal data and data subjects involved. Critical clauses include processor obligations to implement appropriate technical and organizational security measures, process data only on documented instructions, ensure staff confidentiality, and assist with data subject rights requests. Sub-processor arrangements require explicit controller consent or general authorization with specific conditions. The contract must address data breach notification procedures, with processors required to notify controllers without undue delay. Data transfer provisions are essential, particularly for cross-border processing, requiring appropriate safeguards under GDPR Chapter V.

Legal requirements in Netherlands

Netherlands law imposes additional obligations beyond basic GDPR requirements through the Dutch GDPR Implementation Act (UAVG). The agreement must comply with Dutch Civil Code contract formation requirements and include provisions for dispute resolution under Netherlands jurisdiction. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) provides specific guidance on processing agreements, emphasizing the need for clear liability allocation and processor independence. Dutch law requires explicit provisions for data deletion or return upon contract termination, with specific timeframes and verification procedures. The agreement must address Dutch Telecommunications Act requirements when electronic data transmission is involved. Regular auditing rights must be clearly defined, allowing controllers to verify processor compliance with security and procedural obligations under Netherlands data protection standards.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it