MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Drafting a data exchange agreement begins with the question of who determines the purpose of the processing, as this defines the division of roles under the GDPR and, consequently, the structure of the contract. Next, you establish which data is exchanged, on what legal basis (Art. 6 GDPR), with what security measures (Art. 32 GDPR), how to handle data breaches (Art. 33 and 34 GDPR), and whether data is transferred outside the EEA. Without following this sequence, you construct a contract that does not align with the actual relationship between the parties.
The short answer
- Role determination: independent controllers, jointly (Art. 26 GDPR) or processor (Art. 28 GDPR).
- Datascope: which categories of data, in which direction, and for what purpose.
- Legal basis and purpose limitation: on what grounds you share and that the purpose remains limited (Art. 5 and 6 GDPR).
- Security: appropriate technical and organisational measures (Art. 32 GDPR).
- Data breaches and transfer: notification agreements and potential transfer outside the EEA.
Drafting a data exchange agreement: start with the role
The division of roles is the foundation. Determine for each data stream who establishes the purpose and the means. If each party has its own purpose, they are independent controllers and an exchange agreement applies. If the parties determine the purpose jointly, a joint responsibility arrangement applies (Art. 26 GDPR). If one party processes exclusively on the instructions of the other, an exchange agreement is not required, but rather a data processing agreement (Art. 28 GDPR).
This step is often skipped, resulting in a contract that imposes the wrong obligations. Therefore, explicitly state the role in the document so that the applicable regime cannot be disputed afterwards.
Clearly define the data scope
Describe exactly which data is shared. Vaguely described data flows lead to unwanted exchange and violate the purpose limitation of Art. 5 GDPR. Include:
- Categories of data: for example, name and address details, contact details or usage data, and whether it includes special personal data.
- Direction: unilateral or mutual, and designated per stream.
- Purpose: the concrete, well-defined purpose for which the data may be used.
- Legal basis: the basis under Art. 6 GDPR, such as consent, contract, or legitimate interest.
The sharper the scope, the smaller the chance that a party uses data for something for which there is no legal basis.
Security, retention period and data subjects
Document the security measures both parties will take. Art. 32 GDPR requires appropriate technical and organizational measures, tailored to the sensitivity of the data. Consider encryption, access control, and logging. Also agree on retention periods: data that has served its purpose must be deleted.
Additionally, regulate how you handle the rights of data subjects. In the case of independent controllers, each party handles its own requests. In the case of joint responsibility, you establish in the Article 26 Regulation who fulfills the duty to provide information and who handles requests for access, correction, and deletion. This ensures that a data subject knows who to turn to.
Data breaches and transfer
Include a data breach paragraph that aligns with the statutory notification obligation. In principle, a controller reports a data breach to the Data Protection Authority within 72 hours, unless a risk to data subjects is unlikely (Art. 33 GDPR). In the event of a high risk to the rights and freedoms of data subjects, notification to those data subjects also follows (Art. 34 GDPR). Specify who is responsible for which notification and how the parties inform each other directly.
If data leaves the European Economic Area, the requirements of Chapter V of the GDPR (Art. 44 et seq.) apply. State the legal basis for this, such as an adequacy decision or standard contractual clauses. Without that basis, transfer is not permitted.
A practical example: a wholesaler shares order details with a logistics partner who handles the delivery. The partner does not determine the destination themselves but carries out the delivery on behalf of the client. During the drafting process, it becomes apparent that a data processing agreement is appropriate here, rather than an exchange agreement. This prior role check prevents the wholesaler from signing a contract that does not fit the situation.
Final provisions you won't forget
- Confidentiality: mutually, even after the collaboration has ended.
- Liability: who bears which damages in the event of a violation or data breach.
- Duration and termination: what happens to the data at the end of the collaboration.
- Audit: the right to verify compliance with the agreements.
- Applicable law: which law applies and which court has jurisdiction.
Honest recommendation
If you only exchange non-personal data, such as technical or anonymized data, you can easily draft the contract yourself. A clear template with agreements regarding purpose, confidentiality, and security is sufficient, and a lawyer is not necessary.
Do seek assistance as soon as personal data is involved, when the division of roles is not immediately clear, or when data leaves the EEA or involves special categories of personal data. The distinction between independent controllers, Article 26, and Article 28 requires careful attention and affects liability and the risk of fines. An incorrect form cannot simply be corrected retrospectively.
Also read the explanation regarding what a data exchange agreement is and the costs of having a data exchange agreement drafted. You can have a document created via the data exchange agreementpage.
Frequently Asked Questions
Start by defining the roles for each data stream, then establish the data scope, purpose, and legal basis, and arrange for security, retention period, data breach notifications, and any transfer outside the EEA. Conclude with confidentiality, liability, and termination.
Because that determines which GDPR regime applies. Independent controllers, joint responsibility (Art. 26 GDPR), and a processor relationship (Art. 28 GDPR) each require different arrangements. The wrong role leads to a contract that does not reflect reality.
A legal basis under Art. 6 GDPR, such as consent, performance of a contract, or a legitimate interest. The data may only be used for the specific purpose for which they were shared, in accordance with the purpose limitation of Art. 5 GDPR.
Appropriate technical and organizational measures as referred to in Art. 32 GDPR, tailored to the sensitivity of the data. Examples include encryption, access control, logging, and agreements regarding who implements and maintains which measures.
Specify who reports a breach and within what timeframe, following notification to the Data Protection Authority within 72 hours (Art. 33 GDPR) and, in case of high risk, to the data subjects (Art. 34 GDPR). Agree on how the parties will inform each other immediately.
Yes, if data leaves the EEA. State the grounds on which this is permitted under Chapter V of the GDPR (Art. 44 et seq.), for example an adequacy decision or standard contractual clauses. Without a valid legal basis, transfer is not permitted.
For exclusively non-personal data, this is often possible with a good model. For personal data, an unclear division of roles, special categories of data, or transfers outside the EEA, professional review is advisable, as an incorrect form has implications for liability and the risk of fines.