Controller Processor Agreement Template for the Netherlands
Generate a bespoke document
What is a Controller Processor Agreement?
This Controller Processor Agreement is essential for organizations engaged in the processing of personal data under Dutch jurisdiction. It is required whenever an organization (the controller) engages another organization (the processor) to process personal data on its behalf. The agreement ensures compliance with Article 28 of the GDPR and the Dutch GDPR Implementation Act (UAVG), establishing clear responsibilities, security requirements, and accountability measures. It should be implemented before any data processing activities commence and must be maintained throughout the processing relationship. The document includes detailed specifications for data handling, security measures, breach notifications, and audit rights, while addressing specific Dutch legal requirements and regulatory guidelines from the Autoriteit Persoonsgegevens (Dutch Data Protection Authority).
About the Controller Processor Agreement
When you engage a third-party service provider to process personal data on behalf of your organization in the Netherlands, you need a Controller Processor Agreement to ensure GDPR compliance. This legally binding contract establishes the framework for data processing relationships, defining clear responsibilities between the data controller (your organization) and the data processor (the service provider).
When do you need this document?
You must have a Controller Processor Agreement in place whenever you outsource data processing activities to external providers. This includes engaging cloud service providers for data storage, hiring marketing agencies to manage customer databases, using payroll companies to process employee information, or contracting IT support services that access personal data. The agreement is also required when working with sub-processors, such as when your primary processor engages additional third parties. Under Dutch law, this contract must be executed before any processing activities begin, and failure to have proper agreements in place can result in significant fines from the Autoriteit Persoonsgegevens.
Key legal considerations
Your Controller Processor Agreement must include specific mandatory elements under GDPR Article 28. These include detailed descriptions of processing activities, categories of personal data involved, and retention periods. The contract must specify security measures, breach notification procedures within 72 hours, and audit rights allowing you to verify compliance. Data transfer provisions are crucial if processing occurs outside the EU, requiring incorporation of Standard Contractual Clauses or adequacy decisions. The agreement should address processor liability limitations, indemnification clauses, and termination procedures including data return or destruction. You must also consider sub-processing arrangements, ensuring your processor obtains written authorization before engaging additional processors and maintains the same level of data protection.
Legal requirements in Netherlands
Under the Dutch GDPR Implementation Act (UAVG), Controller Processor Agreements must comply with specific national requirements alongside GDPR provisions. The Autoriteit Persoonsgegevens emphasizes that contracts must be written in clear, accessible language and include explicit references to Dutch jurisdiction for dispute resolution. When processing involves cross-border transfers, you must ensure compliance with both EU Standard Contractual Clauses and any additional Dutch safeguards. The agreement must specify applicable Dutch Civil Code provisions for contract validity and enforcement. Organizations processing telecommunications data must also consider requirements under the Dutch Telecommunications Act. The contract should designate authorized representatives within the Netherlands if either party lacks EU establishment, and include specific provisions for cooperation with Dutch supervisory authorities during investigations or audits.
GOVERNING LAW
Applicable law
This Controller Processor Agreement is drafted to comply with Netherlands law. Key legislation includes:
Dutch GDPR Implementation Act (UAVG - Uitvoeringswet AVG): The Dutch national law implementing the GDPR, providing specific national requirements and derogations allowed under the GDPR
Dutch Civil Code (Burgerlijk Wetboek): Provides the legal framework for contracts and agreements under Dutch law, including general contract formation and validity requirements
EU Standard Contractual Clauses (SCCs): If international data transfers are involved, the latest EU SCCs must be considered and potentially incorporated
Dutch Telecommunications Act (Telecommunicatiewet): Relevant if the processing involves electronic communications services or networks
EU Court of Justice Schrems II Decision: Impacts requirements for international data transfers and necessary safeguards that might need to be addressed in the agreement
Dutch Data Protection Authority Guidelines: Specific guidelines and recommendations from the Autoriteit Persoonsgegevens regarding data processing agreements
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it