Controller Processor Agreement Template for the Netherlands

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Controller Processor Agreement?

This Controller Processor Agreement is essential for organizations engaged in the processing of personal data under Dutch jurisdiction. It is required whenever an organization (the controller) engages another organization (the processor) to process personal data on its behalf. The agreement ensures compliance with Article 28 of the GDPR and the Dutch GDPR Implementation Act (UAVG), establishing clear responsibilities, security requirements, and accountability measures. It should be implemented before any data processing activities commence and must be maintained throughout the processing relationship. The document includes detailed specifications for data handling, security measures, breach notifications, and audit rights, while addressing specific Dutch legal requirements and regulatory guidelines from the Autoriteit Persoonsgegevens (Dutch Data Protection Authority).

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Netherlands

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Controller Processor Agreement

When you engage a third-party service provider to process personal data on behalf of your organization in the Netherlands, you need a Controller Processor Agreement to ensure GDPR compliance. This legally binding contract establishes the framework for data processing relationships, defining clear responsibilities between the data controller (your organization) and the data processor (the service provider).

When do you need this document?

You must have a Controller Processor Agreement in place whenever you outsource data processing activities to external providers. This includes engaging cloud service providers for data storage, hiring marketing agencies to manage customer databases, using payroll companies to process employee information, or contracting IT support services that access personal data. The agreement is also required when working with sub-processors, such as when your primary processor engages additional third parties. Under Dutch law, this contract must be executed before any processing activities begin, and failure to have proper agreements in place can result in significant fines from the Autoriteit Persoonsgegevens.

Key legal considerations

Your Controller Processor Agreement must include specific mandatory elements under GDPR Article 28. These include detailed descriptions of processing activities, categories of personal data involved, and retention periods. The contract must specify security measures, breach notification procedures within 72 hours, and audit rights allowing you to verify compliance. Data transfer provisions are crucial if processing occurs outside the EU, requiring incorporation of Standard Contractual Clauses or adequacy decisions. The agreement should address processor liability limitations, indemnification clauses, and termination procedures including data return or destruction. You must also consider sub-processing arrangements, ensuring your processor obtains written authorization before engaging additional processors and maintains the same level of data protection.

Legal requirements in Netherlands

Under the Dutch GDPR Implementation Act (UAVG), Controller Processor Agreements must comply with specific national requirements alongside GDPR provisions. The Autoriteit Persoonsgegevens emphasizes that contracts must be written in clear, accessible language and include explicit references to Dutch jurisdiction for dispute resolution. When processing involves cross-border transfers, you must ensure compliance with both EU Standard Contractual Clauses and any additional Dutch safeguards. The agreement must specify applicable Dutch Civil Code provisions for contract validity and enforcement. Organizations processing telecommunications data must also consider requirements under the Dutch Telecommunications Act. The contract should designate authorized representatives within the Netherlands if either party lacks EU establishment, and include specific provisions for cooperation with Dutch supervisory authorities during investigations or audits.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it