International Data Transfer Addendum Template for the Netherlands
Generate a bespoke document
What is a International Data Transfer Addendum?
The International Data Transfer Addendum is essential when organizations transfer personal data from the Netherlands or other EU countries to recipients outside the EEA. This document becomes necessary when the main data processing agreement needs to be supplemented with specific transfer mechanisms and safeguards required under Chapter V of the GDPR and Dutch data protection law. It incorporates Standard Contractual Clauses, addresses requirements stemming from the Schrems II decision, and includes transfer impact assessments. The addendum is particularly crucial for Dutch organizations engaging with international partners, service providers, or group companies located in third countries, ensuring compliance with both Dutch and EU data protection requirements while facilitating necessary business operations.
Trusted by high-performance teams
About the International Data Transfer Addendum
When your organization transfers personal data from the Netherlands to countries outside the European Economic Area, you need an International Data Transfer Addendum to comply with GDPR requirements. This legal document establishes the necessary safeguards and contractual protections required under Chapter V of the GDPR and Dutch data protection law, ensuring that international data transfers maintain the same level of protection as within the EU.
When do you need this document?
You require an International Data Transfer Addendum whenever you transfer personal data from the Netherlands to third countries that lack an adequacy decision from the European Commission. This includes transfers to cloud service providers in the United States, outsourcing arrangements with companies in Asia, or sharing data with international business partners. The addendum is particularly essential for Dutch companies using international software platforms, engaging global suppliers, or operating subsidiaries outside the EEA. Following the Schrems II decision, you cannot rely solely on Privacy Shield or similar frameworks, making contractual safeguards through this addendum mandatory for most international transfers.
Key legal considerations
Your International Data Transfer Addendum must incorporate the EU Standard Contractual Clauses 2021, which provide binding obligations for both data exporters and importers. The document should include a comprehensive transfer impact assessment addressing the legal system of the recipient country, potential government access to data, and additional safeguards where necessary. You must specify the categories of personal data being transferred, the purposes of processing, and the retention periods. The addendum should establish clear procedures for handling data subject requests, security incident notifications, and regulatory inquiries. Additionally, you need to address sub-processor arrangements and ensure that any onward transfers maintain equivalent protection levels.
Legal requirements in the Netherlands
Under Dutch law, your International Data Transfer Addendum must comply with the Dutch GDPR Implementation Act (UAVG) alongside EU regulations. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) requires that you conduct and document transfer impact assessments before implementing international transfers. You must ensure that the addendum addresses specific Dutch legal requirements regarding data subject rights, including the right to be informed about international transfers in your privacy notices. The document should specify how you will handle requests from Dutch supervisory authorities and provide mechanisms for data subjects to exercise their rights regarding transferred data. When transferring sensitive personal data or data subject to professional secrecy under Dutch law, additional safeguards may be required. Your addendum must also address the territorial scope of Dutch courts and applicable law for dispute resolution, ensuring that Dutch data subjects retain their legal protections even when their data is processed abroad.
GOVERNING LAW
Applicable law
This International Data Transfer Addendum is drafted to comply with Netherlands law. Key legislation includes:
Dutch GDPR Implementation Act: Uitvoeringswet Algemene verordening gegevensbescherming (UAVG) - The Dutch national law implementing and supplementing the GDPR
EU Standard Contractual Clauses 2021: Commission Implementing Decision (EU) 2021/914 - The EU-approved standard contractual clauses for international data transfers to third countries
Dutch Telecommunications Act: Telecommunicatiewet - Contains provisions relevant to electronic communications and data processing in the Netherlands
Schrems II Decision: CJEU Case C-311/18 - Crucial court decision affecting international data transfers and requiring additional safeguards assessment
EDPB Recommendations 01/2020: European Data Protection Board recommendations on measures that supplement transfer tools to ensure compliance with EU level of protection of personal data
Dutch Data Protection Authority Guidelines: Autoriteit Persoonsgegevens (AP) guidelines on international data transfers and implementation of data protection requirements
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

