Joint Controller Agreement Template for the Netherlands
Generate a bespoke document
What is a Joint Controller Agreement?
A Joint Controller Agreement is required under Article 26 GDPR when two or more organizations jointly determine the purposes and means of processing personal data. This document, governed by Dutch law, establishes the framework for compliant joint processing activities, incorporating requirements from both the GDPR and the Dutch GDPR Implementation Act (UAVG). It's essential when organizations collaborate on projects involving personal data processing, such as joint marketing initiatives, shared customer databases, or collaborative research projects. The agreement must transparently allocate responsibilities for GDPR compliance, including handling data subject requests, maintaining security measures, and managing data breaches. It should reflect the specific arrangements between the parties while ensuring compliance with Dutch legal requirements and supervisory authority guidance.
About the Joint Controller Agreement
When your organization collaborates with other companies on projects involving personal data, you need a Joint Controller Agreement to comply with GDPR Article 26 requirements under Netherlands law. This essential legal document establishes clear responsibilities between organizations that jointly determine the purposes and means of personal data processing, ensuring compliance with both European and Dutch data protection regulations.
When do you need this document?
You require a Joint Controller Agreement whenever you and another organization jointly decide how and why personal data is processed. This applies to joint marketing campaigns where you share customer data, collaborative research projects involving participant information, shared loyalty programs across multiple businesses, or when companies merge databases for common purposes. The agreement is also necessary for parent-subsidiary relationships involving shared data processing, group companies coordinating customer service activities, or partnerships where both parties access and use the same personal data sets. Without this agreement, you risk GDPR violations and potential fines from the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Key legal considerations
Your Joint Controller Agreement must clearly define each party's specific responsibilities for GDPR compliance, including who handles data subject requests, maintains security measures, and manages data breaches. The agreement should establish transparent arrangements for data subjects about each controller's role and contact details, as required by GDPR transparency obligations. You need to address liability allocation between joint controllers, ensuring fair distribution of responsibility for any data protection violations or damages. The document must specify how you'll coordinate responses to supervisory authority inquiries and investigations. Additionally, consider including provisions for data transfer mechanisms if processing occurs outside the EU, termination procedures for ending the joint processing relationship, and dispute resolution mechanisms between the controllers.
Legal requirements in Netherlands
Under Netherlands law, your Joint Controller Agreement must comply with the Dutch GDPR Implementation Act (UAVG), which supplements GDPR requirements with specific national provisions. The agreement must be accessible to data subjects upon request, demonstrating transparency about your joint processing arrangements. You should ensure the contract meets Dutch Civil Code requirements for valid agreements, including proper consideration and legal capacity of all parties. The Dutch Telecommunications Act may apply if your joint processing involves electronic communications data, adding additional compliance obligations. Your agreement must designate how you'll interact with the Autoriteit Persoonsgegevens, including which controller serves as the primary contact point for supervisory matters. Consider including clauses addressing Dutch-specific requirements for data breach notifications, which must be reported to the authority within 72 hours of becoming aware of the breach.
GOVERNING LAW
Applicable law
This Joint Controller Agreement is drafted to comply with Netherlands law. Key legislation includes:
Dutch GDPR Implementation Act (UAVG - Uitvoeringswet AVG): The Dutch national law implementing and supplementing the GDPR, providing specific requirements for data protection in the Netherlands
Dutch Civil Code (Burgerlijk Wetboek): Contains general contract law provisions that apply to all agreements in the Netherlands, including requirements for valid contracts and liability provisions
Dutch Telecommunications Act (Telecommunicatiewet): Implementation of the ePrivacy Directive, relevant if the joint processing involves electronic communications data
European Data Protection Board Guidelines on Joint Controllers: While not legislation, these guidelines provide important interpretation and practical guidance on implementing joint controller relationships
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it