MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
If you engage another party to process personal data on your behalf — such as a cloud service provider, accountant, or software supplier — you are required to conclude a data processing agreement that complies with Article 28 of the GDPR. Research by the Dutch Data Protection Authority showed that many entrepreneurs are still working with outdated or incorrect agreements, thereby running an unnecessary risk of fines and claims.
The Dutch Data Protection Authority (AP) published the results of an exploratory study into the use of data processing agreements in the private sector. The picture is anything but rosy: many companies work — often with good intentions — with hopelessly outdated or even incorrect data processing agreements.
What is a data processing agreement?
A data processing agreement is mandatory under privacy legislation as soon as a data controller engages another organization to process personal data on their behalf. This happens more often than you might think: consider a cloud service where data is stored or outsourcing accounting.
Outsourcing tasks does not relieve you of your responsibility: you must continue to ensure proper security and processing. Therefore, in the data processing agreement, you establish agreements regarding, among other things, security, what may and may not be done with the data, and whether sub-processors may be engaged. The specific requirements are set out in Article 28 of the GDPR.
What risks did the AP uncover?
Key conclusions of the study:
- Many data processing agreements do not fully comply with the GDPR, in particular not with the requirements of Article 28, paragraph 3 of the GDPR.
- In some cases, the signing dated from after the information request from the AP — an indication that the agreement was initially not (proper) in place and was only put in order later.
- Many agreements still refer to the Personal Data Protection Act (Wbp), even though the GDPR has been in force since May 25, 2018. Such old documents often do not meet the new requirements, for example regarding the amended duty to provide information.
A good data processing agreement is specialist work
Many controllers find the drafting process complex and consequently use outdated documents or fail to meet the strict requirements. While this was an exploratory study, it shows that entrepreneurs can run into trouble — with a real risk of damage claims and fines or penalties that can run into the tens of thousands of euros.
Frequently Asked Questions
When do I need a data processing agreement?
As soon as another party processes personal data for you, such as a cloud service, accountant, or software supplier, the agreement must comply with Article 28 of the GDPR.
Is my old agreement still valid?
Possibly not. Agreements that still refer to the Wbp or predate the GDPR often no longer comply. Have them checked and replaced if necessary.
What risks do I run with a defective data processing agreement?
In addition to damage claims from affected parties, you risk enforcement by the AP, with fines or penalty payments that can amount to a substantial sum.
Have your data processing agreement drafted or reviewed
The privacy lawyers at MKB Juristen draft a GDPR-compliant data processing agreement or review your existing documents. View our expertise in privacy and data protection or schedule a free intake consultation .