Joint Controller Agreement Template for the Netherlands

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Joint Controller Agreement?

A Joint Controller Agreement is required under Article 26 GDPR when two or more organizations jointly determine the purposes and means of processing personal data. This document, governed by Dutch law, establishes the framework for compliant joint processing activities, incorporating requirements from both the GDPR and the Dutch GDPR Implementation Act (UAVG). It's essential when organizations collaborate on projects involving personal data processing, such as joint marketing initiatives, shared customer databases, or collaborative research projects. The agreement must transparently allocate responsibilities for GDPR compliance, including handling data subject requests, maintaining security measures, and managing data breaches. It should reflect the specific arrangements between the parties while ensuring compliance with Dutch legal requirements and supervisory authority guidance.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Netherlands

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Joint Controller Agreement

When your organization collaborates with other companies on projects involving personal data, you need a Joint Controller Agreement to comply with GDPR Article 26 requirements under Netherlands law. This essential legal document establishes clear responsibilities between organizations that jointly determine the purposes and means of personal data processing, ensuring compliance with both European and Dutch data protection regulations.

When do you need this document?

You require a Joint Controller Agreement whenever you and another organization jointly decide how and why personal data is processed. This applies to joint marketing campaigns where you share customer data, collaborative research projects involving participant information, shared loyalty programs across multiple businesses, or when companies merge databases for common purposes. The agreement is also necessary for parent-subsidiary relationships involving shared data processing, group companies coordinating customer service activities, or partnerships where both parties access and use the same personal data sets. Without this agreement, you risk GDPR violations and potential fines from the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Key legal considerations

Your Joint Controller Agreement must clearly define each party's specific responsibilities for GDPR compliance, including who handles data subject requests, maintains security measures, and manages data breaches. The agreement should establish transparent arrangements for data subjects about each controller's role and contact details, as required by GDPR transparency obligations. You need to address liability allocation between joint controllers, ensuring fair distribution of responsibility for any data protection violations or damages. The document must specify how you'll coordinate responses to supervisory authority inquiries and investigations. Additionally, consider including provisions for data transfer mechanisms if processing occurs outside the EU, termination procedures for ending the joint processing relationship, and dispute resolution mechanisms between the controllers.

Legal requirements in Netherlands

Under Netherlands law, your Joint Controller Agreement must comply with the Dutch GDPR Implementation Act (UAVG), which supplements GDPR requirements with specific national provisions. The agreement must be accessible to data subjects upon request, demonstrating transparency about your joint processing arrangements. You should ensure the contract meets Dutch Civil Code requirements for valid agreements, including proper consideration and legal capacity of all parties. The Dutch Telecommunications Act may apply if your joint processing involves electronic communications data, adding additional compliance obligations. Your agreement must designate how you'll interact with the Autoriteit Persoonsgegevens, including which controller serves as the primary contact point for supervisory matters. Consider including clauses addressing Dutch-specific requirements for data breach notifications, which must be reported to the authority within 72 hours of becoming aware of the breach.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it