MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
To be GDPR-compliant, virtually every organization needs a number of documents: a data processing agreement, a privacy and cookie statement, privacy regulations, a data breach protocol, and a consent form for visual content. These documents demonstrate that you have taken the required measures — and prevent fines, reputational damage, and damage claims. Below, you can read which five documents you need to have in order.
Why GDPR documentation?
The GDPR requires you to handle the personal data of customers and employees carefully and transparently. Compliance prevents not only fines but also reputational damage and damage claims. An important part of this is drafting documents that demonstrate that you have taken the required measures.
1. Data Processor Agreement
The data processing agreement is a contract between the data controller and the data processor. It ensures that the processor uses the data only for the agreed purpose and adequately secures it. It is indispensable if you outsource processing, such as cloud storage or payroll. The agreement describes, among other things, the purpose, duration, nature and type of data, and the rights and obligations of both parties.
2. Privacy and cookie statement
Virtually every organization with a website must have a privacy and cookie statement. This explains which personal data is collected, why, and how cookies are used, plus how visitors can view, modify, or delete their data. It is not only webshops that are required to do so.
3. Privacy Policy
A privacy policy provides customers and employees with clarity regarding which personal data you collect, why, and with whom you share it. It also explains the GDPR rights of data subjects, such as the right of access, correction, and deletion. Required for every organization that processes personal data.
4. Data Breach Protocol
The data breach protocol describes the steps you take as soon as a data breach is discovered, including reporting to the Dutch Data Protection Authority and — if necessary — to the data subjects. Crucial for every organization that processes personal data.
5. Permission to use employee image material
With a consent form, you obtain permission to use photos and videos of employees for communication purposes, for example on your website, in brochures, or on social media.
Frequently Asked Questions
Which GDPR documents does my organization need at a minimum?
Typically a privacy and cookie statement, privacy regulations, and a data breach protocol, plus a data processing agreement if you outsource processing. Often also a processing register.
Do I only need a privacy statement if I have a webshop?
No. Virtually every organization with a website that processes personal data needs a privacy and cookie statement.
When do I need a data processing agreement?
If you outsource processing to a party that processes personal data on your behalf, such as a cloud or payroll provider.
May I put photos of employees on the website?
Only with valid permission. Record this in a consent form for the use of visual material.
Have your organization made GDPR-compliant
We draft these and other documents, such as a GDPR processing register, and ensure they are clear and correct. During a GDPR screening, we map out all your needs.
View our GDPR package or schedule a no-obligation consultation.