Controller To Controller Agreement Template for the Netherlands

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Controller To Controller Agreement?

The Controller to Controller Agreement is essential when two organizations, acting as independent data controllers, need to share personal data while maintaining GDPR compliance. This agreement is particularly relevant under Dutch law, where both the EU GDPR and the Dutch Implementation Act (UAVG) apply. It should be used whenever organizations plan to exchange personal data for specific purposes while each maintaining separate control over their processing activities. The document addresses key compliance requirements including data protection principles, security measures, breach notification procedures, and data subject rights. It's designed to provide a clear framework for data sharing activities while ensuring each controller understands and can meet their respective obligations under Dutch and EU data protection law.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Netherlands

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Controller To Controller Agreement

When two organizations in the Netherlands need to share personal data while operating as independent data controllers, you require a Controller to Controller Agreement to ensure GDPR compliance. This legal document establishes the framework for lawful data sharing between entities that each maintain control over their own processing activities, distinguishing it from controller-processor relationships covered by separate agreements.

When do you need this document?

You need this agreement when your organization plans to share personal data with another company for mutual business purposes. Common scenarios include joint marketing campaigns where both companies use customer data for their own promotional activities, research collaborations between institutions sharing participant data, or business partnerships where customer information is exchanged for service delivery. The agreement is also essential when merging datasets for analytics purposes, sharing employee information during corporate restructuring, or collaborating on projects requiring access to each other's customer databases. Under Dutch law, any data sharing arrangement between independent controllers requires documented legal basis and clear allocation of responsibilities.

Key legal considerations

Your agreement must establish a lawful basis for processing under Article 6 of the GDPR, whether legitimate interest, contract performance, or consent. You need to clearly define the purpose limitation principle, specifying exactly why data is being shared and preventing use beyond agreed purposes. Data minimization clauses ensure only necessary data categories are exchanged, while accuracy provisions require both parties to maintain up-to-date information. Security measures must meet GDPR Article 32 requirements, including technical and organizational safeguards appropriate to the risk level. Breach notification procedures should establish timelines for informing each other and supervisory authorities within 72 hours. Data subject rights provisions must clarify how both controllers will handle access requests, corrections, deletions, and objections. International transfer clauses become critical if either party operates outside the EU, requiring adequate safeguards or Standard Contractual Clauses.

Legal requirements in Netherlands

Under the Dutch GDPR Implementation Act (UAVG), you must register your data processing activities with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if required by law. The agreement must comply with Dutch contract law under the Civil Code (Burgerlijk Wetboek), ensuring valid formation and enforceability. If telecommunications data is involved, additional requirements under the Dutch Telecommunications Act may apply. You need to designate Data Protection Officers if either organization meets the GDPR thresholds, and their contact details must be included in the agreement. Dutch law requires specific language regarding liability allocation between controllers, particularly for data protection violations and associated fines. The agreement should reference Dutch jurisdiction for dispute resolution and specify which party bears responsibility for data subject compensation claims under Article 82 of the GDPR.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it