To undertake

Drafting a data exchange agreement: this is what should be included

Drafting a data exchange agreement? Read which components should be included, common mistakes, and when to hire a lawyer.

Published on August 16, 2026 by MKBjuristen.nl
Request a free quote Call 085 25000 44

MKB Juristen drafts custom legal documents

It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.

  • Custom contracts, terms and conditions, and legal documents
  • Budget-friendly and clear about the costs upfront
  • Request a free consultation or a no-obligation quote
Free consultation Request a free quote

Drafting a data exchange agreement begins with the question of who determines the purpose of the processing, as this defines the division of roles under the GDPR and, consequently, the structure of the contract. Next, you establish which data is exchanged, on what legal basis (Art. 6 GDPR), with what security measures (Art. 32 GDPR), how to handle data breaches (Art. 33 and 34 GDPR), and whether data is transferred outside the EEA. Without following this sequence, you construct a contract that does not align with the actual relationship between the parties.

The short answer

  1. Role determination: independent controllers, jointly (Art. 26 GDPR) or processor (Art. 28 GDPR).
  2. Datascope: which categories of data, in which direction, and for what purpose.
  3. Legal basis and purpose limitation: on what grounds you share and that the purpose remains limited (Art. 5 and 6 GDPR).
  4. Security: appropriate technical and organisational measures (Art. 32 GDPR).
  5. Data breaches and transfer: notification agreements and potential transfer outside the EEA.

Drafting a data exchange agreement: start with the role

Drafting a data exchange agreement: first determine the division of roles under the GDPR

The division of roles is the foundation. Determine for each data stream who establishes the purpose and the means. If each party has its own purpose, they are independent controllers and an exchange agreement applies. If the parties determine the purpose jointly, a joint responsibility arrangement applies (Art. 26 GDPR). If one party processes exclusively on the instructions of the other, an exchange agreement is not required, but rather a data processing agreement (Art. 28 GDPR).

This step is often skipped, resulting in a contract that imposes the wrong obligations. Therefore, explicitly state the role in the document so that the applicable regime cannot be disputed afterwards.

Clearly define the data scope

Describe exactly which data is shared. Vaguely described data flows lead to unwanted exchange and violate the purpose limitation of Art. 5 GDPR. Include:

  • Categories of data: for example, name and address details, contact details or usage data, and whether it includes special personal data.
  • Direction: unilateral or mutual, and designated per stream.
  • Purpose: the concrete, well-defined purpose for which the data may be used.
  • Legal basis: the basis under Art. 6 GDPR, such as consent, contract, or legitimate interest.

The sharper the scope, the smaller the chance that a party uses data for something for which there is no legal basis.

Security, retention period and data subjects

Agreements on security, retention period, and rights of data subjects

Document the security measures both parties will take. Art. 32 GDPR requires appropriate technical and organizational measures, tailored to the sensitivity of the data. Consider encryption, access control, and logging. Also agree on retention periods: data that has served its purpose must be deleted.

Additionally, regulate how you handle the rights of data subjects. In the case of independent controllers, each party handles its own requests. In the case of joint responsibility, you establish in the Article 26 Regulation who fulfills the duty to provide information and who handles requests for access, correction, and deletion. This ensures that a data subject knows who to turn to.

Data breaches and transfer

Data breach notification agreements and rules for transfers outside the EEA

Include a data breach paragraph that aligns with the statutory notification obligation. In principle, a controller reports a data breach to the Data Protection Authority within 72 hours, unless a risk to data subjects is unlikely (Art. 33 GDPR). In the event of a high risk to the rights and freedoms of data subjects, notification to those data subjects also follows (Art. 34 GDPR). Specify who is responsible for which notification and how the parties inform each other directly.

If data leaves the European Economic Area, the requirements of Chapter V of the GDPR (Art. 44 et seq.) apply. State the legal basis for this, such as an adequacy decision or standard contractual clauses. Without that basis, transfer is not permitted.

A practical example: a wholesaler shares order details with a logistics partner who handles the delivery. The partner does not determine the destination themselves but carries out the delivery on behalf of the client. During the drafting process, it becomes apparent that a data processing agreement is appropriate here, rather than an exchange agreement. This prior role check prevents the wholesaler from signing a contract that does not fit the situation.

Final provisions you won't forget

  • Confidentiality: mutually, even after the collaboration has ended.
  • Liability: who bears which damages in the event of a violation or data breach.
  • Duration and termination: what happens to the data at the end of the collaboration.
  • Audit: the right to verify compliance with the agreements.
  • Applicable law: which law applies and which court has jurisdiction.

Honest recommendation

Legal expert checks a drafted data exchange agreement for GDPR roles

If you only exchange non-personal data, such as technical or anonymized data, you can easily draft the contract yourself. A clear template with agreements regarding purpose, confidentiality, and security is sufficient, and a lawyer is not necessary.

Do seek assistance as soon as personal data is involved, when the division of roles is not immediately clear, or when data leaves the EEA or involves special categories of personal data. The distinction between independent controllers, Article 26, and Article 28 requires careful attention and affects liability and the risk of fines. An incorrect form cannot simply be corrected retrospectively.

Also read the explanation regarding what a data exchange agreement is and the costs of having a data exchange agreement drafted. You can have a document created via the data exchange agreementpage.

Frequently Asked Questions

How do you draw up a data exchange agreement?

Start by defining the roles for each data stream, then establish the data scope, purpose, and legal basis, and arrange for security, retention period, data breach notifications, and any transfer outside the EEA. Conclude with confidentiality, liability, and termination.

Why do I start with the division of roles?

Because that determines which GDPR regime applies. Independent controllers, joint responsibility (Art. 26 GDPR), and a processor relationship (Art. 28 GDPR) each require different arrangements. The wrong role leads to a contract that does not reflect reality.

What legal basis do I need to share data?

A legal basis under Art. 6 GDPR, such as consent, performance of a contract, or a legitimate interest. The data may only be used for the specific purpose for which they were shared, in accordance with the purpose limitation of Art. 5 GDPR.

What should I include regarding security?

Appropriate technical and organizational measures as referred to in Art. 32 GDPR, tailored to the sensitivity of the data. Examples include encryption, access control, logging, and agreements regarding who implements and maintains which measures.

How do I handle data breaches in the contract?

Specify who reports a breach and within what timeframe, following notification to the Data Protection Authority within 72 hours (Art. 33 GDPR) and, in case of high risk, to the data subjects (Art. 34 GDPR). Agree on how the parties will inform each other immediately.

Do I need to arrange anything regarding transfers outside the EEA?

Yes, if data leaves the EEA. State the grounds on which this is permitted under Chapter V of the GDPR (Art. 44 et seq.), for example an adequacy decision or standard contractual clauses. Without a valid legal basis, transfer is not permitted.

Can I draft it myself?

For exclusively non-personal data, this is often possible with a good model. For personal data, an unclear division of roles, special categories of data, or transfers outside the EEA, professional review is advisable, as an incorrect form has implications for liability and the risk of fines.

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

A blog provides explanation, but your situation often requires a concrete legal choice. MKB Juristen helps entrepreneurs with contracts, terms and conditions, GDPR documents, employment documents, disputes, and customized legal solutions.

Drafting, reviewing, and amending contracts
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

August 23, 2026

What is a general terms and conditions scan? Function and legal status

What is a Terms and Conditions scan? Explanation of the function, when you need it, and what to look out for as an SME.

August 23, 2026

Drafting a disclaimer of liability: this is what belongs in it

Drafting a disclaimer of liability? Read which components should be included, common mistakes, and when to hire a lawyer.

August 23, 2026

Drafting a model contract for personal data outside the EU: this should be included

Drafting a model contract for personal data outside the EU? Read which components should be included, common mistakes, and when to consult a lawyer.

August 23, 2026

Drafting an internal employee privacy statement: what belongs in it

Drafting an internal employee privacy statement? Read about the components that should be included, common mistakes, and when to hire a lawyer.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation