Personal Data Transfer Agreement Template for the Netherlands
Generate a bespoke document
What is a Personal Data Transfer Agreement?
The Personal Data Transfer Agreement is essential for organizations transferring personal data under Dutch jurisdiction, whether domestically or internationally. This document becomes necessary when personal data needs to be shared between different entities, such as between a company and its service providers, or between group companies. It ensures compliance with the GDPR, Dutch GDPR Implementation Act (UAVG), and other relevant Dutch privacy laws. The agreement includes detailed provisions on data processing activities, security measures, breach notifications, and data subject rights. It's particularly crucial for international transfers where additional safeguards may be required under Chapter V of the GDPR. The document should be customized based on the specific nature of data transfer, processing purposes, and the roles of the parties involved (controller-processor or controller-controller relationships).
About the Personal Data Transfer Agreement
A Personal Data Transfer Agreement is a crucial legal document that governs how personal data is shared between organizations under Dutch law. You need this agreement to ensure compliance with the GDPR, Dutch GDPR Implementation Act (UAVG), and other relevant privacy regulations when transferring personal data either domestically within the Netherlands or internationally.
When do you need this document?
You require a Personal Data Transfer Agreement whenever you share personal data with external parties, such as service providers, business partners, or subsidiaries. This includes scenarios where you engage cloud storage providers, marketing agencies, payroll processors, or IT support companies that will access your customer or employee data. The agreement is also essential when establishing data sharing arrangements between group companies or when outsourcing specific business functions that involve personal data processing. For international transfers to countries outside the European Economic Area, this document becomes mandatory to demonstrate adequate safeguards under Chapter V of the GDPR.
Key legal considerations
Your agreement must clearly define the roles of each party as either data controller or data processor, as this determines their respective obligations under Dutch law. You need to specify the categories of personal data being transferred, the purposes of processing, and the retention periods. Security measures and technical safeguards must be detailed to protect data during transfer and subsequent processing. The agreement should include breach notification procedures, ensuring both parties understand their obligations to report incidents to the Dutch Data Protection Authority within 72 hours. Data subject rights provisions are crucial, outlining how individuals can exercise their rights to access, rectification, erasure, and data portability. For international transfers, you must incorporate Standard Contractual Clauses (SCCs) approved by the European Commission or demonstrate other adequate safeguards.
Legal requirements in Netherlands
Under Dutch law, your Personal Data Transfer Agreement must comply with the GDPR as implemented through the Dutch GDPR Implementation Act (UAVG). The agreement must establish a lawful basis for processing under Article 6 GDPR, whether it's contract performance, legitimate interest, or consent. You're required to conduct and document a Data Protection Impact Assessment (DPIA) for high-risk transfers, particularly those involving international destinations. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has specific guidance on cross-border transfers that must be followed. Your agreement should also comply with Dutch Civil Code provisions regarding contract formation and validity. If the transfer involves electronic communications data, additional requirements under the Dutch Telecommunications Act may apply. The document must be available in Dutch if requested by data subjects, and you should maintain records of processing activities as required under Article 30 GDPR.
GOVERNING LAW
Applicable law
This Personal Data Transfer Agreement is drafted to comply with Netherlands law. Key legislation includes:
Dutch GDPR Implementation Act (UAVG): Dutch law implementing the GDPR (Uitvoeringswet AVG), providing specific national rules and derogations allowed under GDPR
Dutch Civil Code (Burgerlijk Wetboek): Contains general contract law provisions that govern the formation and validity of agreements under Dutch law
Standard Contractual Clauses (SCCs): EU Commission approved contractual clauses for international data transfers to third countries, mandatory when transferring data outside EEA
Dutch Telecommunications Act (Telecommunicatiewet): Relevant if the data transfer involves electronic communications data or requires telecommunications infrastructure
Dutch Constitution (Grondwet): Article 10 specifically protects the right to privacy and personal data protection
Dutch Data Protection Authority Guidelines: Guidance and interpretations issued by the Dutch DPA (Autoriteit Persoonsgegevens) regarding data transfers and processing
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it