Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Controller Processor Agreement
"I need a Controller Processor Agreement under Dutch law for our cloud software company that will be processing customer data in both the Netherlands and Singapore, with implementation planned for March 2025; must include international transfer clauses and sub-processor provisions."
1. Parties: Identification of the Controller and Processor, including full legal names, registration details, and authorized representatives
2. Background: Context of the relationship between parties and purpose of the agreement
3. Definitions: Key terms used in the agreement, including GDPR-specific terminology
4. Scope and Purpose of Processing: Detailed description of the data processing activities, categories of data subjects, and types of personal data
5. Duration and Termination: Term of the agreement, termination conditions, and data handling upon termination
6. Obligations of the Processor: Core processor obligations under GDPR Article 28, including processing only on documented instructions
7. Security Measures: Technical and organizational measures implemented to ensure appropriate security of processing
8. Confidentiality: Confidentiality obligations regarding personal data and processing activities
9. Data Subject Rights: Processor's assistance in responding to data subject requests
10. Personal Data Breaches: Notification requirements and cooperation in case of data breaches
11. Audit Rights: Controller's audit rights and processor's obligations to demonstrate compliance
12. Liability and Indemnification: Allocation of liability and indemnification obligations
13. Governing Law and Jurisdiction: Specification of Dutch law as governing law and jurisdiction for disputes
1. International Data Transfers: Required when personal data will be transferred outside the EEA, including appropriate transfer mechanisms
2. Sub-processor Provisions: Required when the processor intends to engage sub-processors, including authorization process
3. Insurance Requirements: Optional section specifying required insurance coverage for data processing activities
4. Business Continuity: Optional section detailing business continuity and disaster recovery requirements
5. Data Protection Impact Assessments: Required when processing is likely to result in high risk to individuals
6. Specific Industry Requirements: Optional section for industry-specific data protection requirements (e.g., healthcare, financial services)
1. Schedule 1 - Processing Activities: Detailed description of processing activities, including categories of data, purposes, and duration
2. Schedule 2 - Technical and Organizational Measures: Detailed description of security measures implemented by the processor
3. Schedule 3 - Approved Sub-processors: List of approved sub-processors and their processing activities
4. Schedule 4 - Transfer Mechanisms: Details of transfer mechanisms for international data transfers, including SCCs if applicable
5. Schedule 5 - Security Breach Response Plan: Detailed procedures for handling and reporting personal data breaches
6. Appendix A - Contact Details: Contact information for key personnel and data protection officers
7. Appendix B - Audit Procedures: Detailed procedures for conducting compliance audits
Authors
Applicable Data Protection Laws
Authorized Persons
Authorized Sub-processor
Confidential Information
Controller
Data Protection Impact Assessment
Data Protection Laws
Data Subject
Data Subject Rights
Dutch Data Protection Authority
EEA
GDPR
Information Security Incident
International Transfer
Personal Data
Personal Data Breach
Processing
Processor
Professional Services
Restricted Transfer
Security Measures
Services
Special Categories of Personal Data
Standard Contractual Clauses
Sub-processor
Supervisory Authority
Technical and Organizational Measures
Term
Third Country
UAVG
Working Day
Definitions
Scope
Duration
Data Protection Obligations
Processing Instructions
Confidentiality
Security
Sub-processing
Data Subject Rights
Data Breach Notification
Audit Rights
International Transfers
Compliance Assistance
Data Return and Deletion
Liability
Indemnification
Insurance
Force Majeure
Termination
Notices
Assignment
Severability
Entire Agreement
Amendments
Governing Law
Jurisdiction
Dispute Resolution
Technology and Software
Healthcare
Financial Services
E-commerce
Professional Services
Education
Manufacturing
Telecommunications
Retail
Insurance
Human Resources
Marketing and Advertising
Cloud Services
Research and Development
Public Sector
Legal
Privacy
Compliance
Information Security
IT
Risk Management
Operations
Procurement
Data Protection
Information Governance
Vendor Management
Contract Management
Data Protection Officer
Privacy Officer
Legal Counsel
Compliance Manager
Information Security Manager
Privacy Manager
Contract Manager
Risk Manager
IT Director
Chief Information Security Officer
Chief Privacy Officer
General Counsel
Operations Manager
Project Manager
Procurement Manager
Find the exact document you need
International Data Transfer Addendum
Dutch law-governed International Data Transfer Addendum for GDPR-compliant personal data transfers from the Netherlands/EU to non-EEA countries.
Intra Group Data Processing Agreement
Dutch law-governed data processing agreement for intra-group personal data transfers and processing, ensuring GDPR compliance within corporate groups.
Controller To Controller Agreement
A Dutch law-governed agreement between two data controllers establishing terms for compliant personal data sharing under GDPR and UAVG.
Product Development Non Disclosure Agreement
Dutch law-governed NDA for protecting confidential information in product development activities, including technical specifications and intellectual property.
Data Processing Contract
Dutch law-governed Data Processing Contract establishing GDPR-compliant terms between controller and processor.
Joint Controller Agreement
A Dutch law-governed agreement establishing responsibilities and obligations between joint controllers under GDPR and UAVG for shared data processing activities.
Dpia Agreement
A Dutch law agreement establishing the framework for conducting Data Protection Impact Assessments (DPIAs) in compliance with GDPR and local privacy regulations.
Data Processing Addendum
A Dutch law-governed agreement establishing GDPR-compliant terms for personal data processing between a controller and processor.
Data Agreement
A Dutch law-governed agreement establishing terms for data processing and sharing, ensuring compliance with Dutch and EU data protection regulations.
Data Addendum
A Dutch law-governed supplementary agreement that adds GDPR and UAVG-compliant data protection terms to an existing contract.
Third Party Processor Agreement
A Dutch law-governed agreement establishing terms for third-party processing of personal data under GDPR and UAVG requirements.
Intercompany Data Processing Agreement
A Dutch law-governed agreement regulating personal data processing between affiliated companies within the same corporate group, ensuring GDPR compliance.
Third Party Data Processing Agreement
Dutch law-governed agreement establishing GDPR-compliant terms for third-party processing of personal data, aligned with both EU and Dutch data protection requirements.
Controller Processor Agreement
A Dutch law-governed agreement establishing GDPR-compliant terms for personal data processing between controller and processor.
Order Processing Agreement
A Dutch-law governed agreement between a data controller and processor establishing terms for personal data processing under GDPR and Dutch UAVG requirements.
Affiliate Addendum
Dutch law-governed addendum for affiliate marketing arrangements, outlining partnership terms, commissions, and compliance requirements.
Sub Processing Agreement
Dutch law-governed agreement between a processor and sub-processor for GDPR-compliant data processing activities.
International Data Transfer Agreement
Dutch law-governed agreement for international personal data transfers, incorporating EU Standard Contractual Clauses and GDPR compliance measures.
Data Protection Addendum
Dutch law-governed data protection addendum establishing GDPR-compliant terms for personal data processing between controllers and processors.
Download our whitepaper on the future of AI in Legal
Genie’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; Genie’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our Trust Centre for more details and real-time security updates.
Read our Privacy Policy.