Custom legal document

Processors-an agreement drafting

Have it drafted, amended, or reviewed by our legal experts and/or lawyers starting from 99
SME Lawyers

Do not hastily put this document together yourself — a false sense of security is harmful.
Have a specialist screen it and be in a stronger position when it matters.

  • Truly Tailor-Made Legal Solutions
  • Fixed rates
  • Pay later after draft
  • Free adjustment round
  • Delivered within 5 working days
  • Express delivery possible
  • Available in Dutch and English

How does it work?
Our services include a free consultation, a draft document, a revision round, and a final document. We invoice after sending the draft document.

Experience with legal services for entrepreneurs since 2001
Lawyers and legal professionals.Direct contact with a specialist who thinks practically.
Fixed rates.Where possible, clarity regarding costs in advance.
Within 4 hoursWe respond quickly to your request.
  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner

We worked for, among others:

An incorrect document often provides a false sense of security.
You think everything is taken care of, but only discover whether the document actually works during a conflict or claim.

1

Free intake

We discuss your company, the purpose of the document, and the key risks.

2

Draft or check

We draft a custom document or review your existing document legally.

3

Final version

You will receive a final version with instructions on correct usage.

Mr. Jaime Boogaers
Mr. Jaime Boogaers
Corporate Law
Attorney, 16 years of experience

A data processing agreement is more than a GDPR annex. The core is that it clarifies who is the controller, who is the processor, which instructions apply, and how security, data breaches, sub-processors, and the termination of services are handled

  • For clients, SaaS providers, IT suppliers, marketing agencies, and service providers
  • Attention to GDPR roles, processing purposes, security, and instructions
  • Subprocessors, data breaches, audits, transfer, retention periods, and exit arranged
  • Practically usable alongside SaaS, service, contract, or cooperation agreements

Choose Tailored Legal Solutions

Choose whether you want to have the document drafted, checked, or modified. Prices and options vary per document.

From 99
Customization
from 99.- per document

Do you already have a document, but are unsure if it is still correct? We check content, risks, and practical usability.

from 249.- per document

Is your document outdated, copied, generated with AI, or no longer suitable? We check and adjust the document.

About us

Our expertise in data processing agreements

Our lawyers and in-house counsel assist clients, SaaS providers, IT companies, marketing agencies, administration offices, and service providers with data processing agreements, privacy statements, SaaS contracts, service agreements, and privacy addendums. We examine GDPR roles, data categories, security, sub-processors, data breaches, audits, transfer, exit, and liability.

Custom solutions for your data processing

A data processing agreement for SaaS, IT management, marketing, administration, payroll processing, or healthcare data does not require the same arrangements. Therefore, we tailor the agreement to the systems, data, risk, sub-processors, and main contract.

Our facts

  • Active since 2001
  • Lawyers and in-house counsel
  • Experience with privacy, corporate law, employment law, and contract law
  • Attention to practical operation, risks, and enforceability
  • Fixed rates in advance where possible
  • Customization
  • About us
from 99.- per document

Do you already have a document, but are unsure if it is still correct? We check content, risks, and practical usability.

  • Our legal expert spends 0.5 to 1.5 hours on the check
  • Telephone intake with a lawyer
  • Checks on content, risks, and practical usability
  • Attention to liability, payment, and termination
  • Concrete points for improvement and legal advice
  • Delivered within 3 working days, express delivery possible
from 249.- per document

Is your document outdated, copied, generated with AI, or no longer suitable? We check and adjust the document.

  • Our legal expert spends 1.5 to 2.5 hours checking and making adjustments
  • Telephone intake with a lawyer
  • Verification of the existing document
  • Adaptation to your business and working methods
  • Suitable for new services, customers, or risks
  • Delivered within 5 working days, express delivery possible

About us

Our expertise in data processing agreements

Our lawyers and in-house counsel assist clients, SaaS providers, IT companies, marketing agencies, administration offices, and service providers with data processing agreements, privacy statements, SaaS contracts, service agreements, and privacy addendums. We examine GDPR roles, data categories, security, sub-processors, data breaches, audits, transfer, exit, and liability.

Custom solutions for your data processing

A data processing agreement for SaaS, IT management, marketing, administration, payroll processing, or healthcare data does not require the same arrangements. Therefore, we tailor the agreement to the systems, data, risk, sub-processors, and main contract.

Our facts

  • Active since 2001
  • Lawyers and in-house counsel
  • Experience with privacy, corporate law, employment law, and contract law
  • Attention to practical operation, risks, and enforceability
  • Fixed rates in advance where possible

Reviews (21)

Tijn

The speed of action pleasantly surprised us. Communication was always handled through a single point of contact, which prevented confusion. The document was accepted flawlessly by our investors.

Jan

Received pleasant assistance from the first contact. The fixed price upfront instilled confidence. Everything was delivered neatly and on time.

Reda

The decisiveness during the first meeting was very pleasant. They immediately understood where the sensitivities lay within our collaboration. Our customers are responding positively to the clear general terms and conditions.

Sebastian

The expertise was immediately evident from the first contact. The speed with which complex legislative changes were integrated into our document was excellent. Our clients are responding positively to the clear general terms and conditions.

Ilse

The clear start gave us a lot of confidence for the rest of the process. We were also able to ask questions after receiving the document. The document was accepted flawlessly by our investors.

Renate

We needed tailored legal solutions quickly and received excellent assistance. The discussion regarding specific non-compete clauses was handled very professionally. Our business partners were impressed by the professionalism of the contracts.

Laura

The energetic and positive attitude of the employees was immediately noticeable. The comments were concrete and directly usable. The quality fully met our expectations.

Nora

It was a relief to be helped so quickly. We received excellent advice regarding the division of intellectual property rights. The service was professional and personal.

Remco

My application via the website was picked up super fast. The personal involvement made us feel truly supported. These documents will undoubtedly save us a lot of headaches in the future.

Sanne

It immediately felt like a partnership rather than a simple service. The risks we were willing to take were assessed strictly but fairly. Our business partners were impressed by the professionalism of the contracts.

Hans

We were immediately assigned a dedicated contact person, which worked very well. The corrections were always implemented lightning-fast in the new version. A company that delivers on what it promises on the website.

Asmae

The initial meeting confirmed that we had made the right choice. They managed to reduce an extremely tough file to manageable proportions. The end result aligns 100% with our high standards.

Saar

We received pleasant assistance from the very first contact. They did not make things unnecessarily difficult regarding minor changes outside the scope. The document was accepted flawlessly by our investors.

Eva

It was nice that we knew immediately who would be helping us. The delivery was within the agreed timeframe. These documents will undoubtedly save us a lot of headaches in the future.

Safae

The direct contact and the absence of hidden costs were the deciding factors. We were also able to ask questions after the initial consultation. Fantastic value for money for this level of expertise.

Patrick

From the intake, it was clear what we could expect. The lawyer's patience in explaining the liability clauses was admirable. Everything was delivered neatly and on time.

Houda

We quickly received the right guidance in a legal landscape unfamiliar to us. Our questions were answered calmly and clearly. The quality fully met our expectations.

Hanane

The consultation provided immediate clarity. We received an excellent explanation regarding the implications of applicable law in our international contracts. Everything was delivered neatly and on time.

Said

The start of the process immediately made a professional impression. We received a clear document without unnecessary complexity. A party that delivers on what it promises on its website.

Liam

The proactive approach began even before the quotation was signed. The advice regarding the employment contracts was fully in accordance with the latest legislation. The final result aligns 100% with our high standards.

Ibrahim

We really appreciated the transparency regarding the costs upfront. The aftercare and the opportunity to ask brief questions were perfectly arranged. A reliable partner that strives for perfection in their documents.

Meet our office

Our ContractCheck, simply explained what can all go wrong.

Why MKB Juristen?

Since 2001, we have been active as a no-nonsense legal firm for entrepreneurs. We quickly get to the heart of the matter: with a thorough assessment, clear answers, and a document that works practically.

  • Nationwide coverage
  • First consultation free and without obligation
  • Fixed rates where possible
  • Affordable legal advice from lawyers and legal experts
  • Always a response within 4 hours

First, see how we work

A legal document requires trust. You see immediately who we are, how we help entrepreneurs, and why we do not work with standard templates.

  • You can view our working method before submitting an application
  • You will get a feel for the office and the people faster
  • The video supports the choice for customized legal solutions
  • After that, you can immediately request a quote or intake

What you can expect from us

We translate your situation into a legal document that you can actually use. You won't receive a loose template, but a document tailored to your business, agreements, and risks.

  • A clear roadmap: intake, concept, revision round, and final version
  • Practical explanation on how to use the document
  • Legal attention to liability, payment, and termination
  • Where possible, provide clarity in advance regarding price and delivery time
Are you unsure whether you should have the document drafted, checked, or amended?
During the initial consultation, we will determine the sensible course of action together. Afterward, you will know exactly where you stand.

Why customization?

A legal document only works well if it aligns with your business, agreements, risks, and industry. That is why we do not work with a standard generator, but with legal experts who assess your situation.

  • Prepared for your company
  • Telephone consultation included
  • No standard template
  • Review by legal specialists

What do you get?

You will receive a legal document that is practical and aligns with the agreements you wish to make.

  • Draft document or legal review
  • One adjustment round
  • Clear explanation where necessary
  • Fixed price where possible

The founders of MKB Juristen

Our organization consists of several small teams working within various legal fields. Each legal field has its own senior in-house counsel and/or lawyers.

Denian Wielhouwer

Corporate lawyer in corporate law & business expert

Denian Wielhouwer

Annelore Hendriks

Corporate lawyer, corporate law, administrative law

Annelore Hendriks

Ilja van Driel

Corporate law attorney, employment law

Ilja van Driel

Jaime Boogaers

Corporate law, ICT & privacy law, energy law attorney

Jaime Boogaers
Custom choices

Which choices determine the content?

The precise content of your data processing agreement depends on the relationship with the processor and the sensitivity of the data. The questions below will help you make the right choices.

Choice or question Why this matters legally
Are you a data controller or a data processor yourself? Determines whether you give or receive the instructions; in the case of joint responsibility, a different arrangement (Article 26 GDPR) is required.
May the processor engage sub-processors? Choose between prior consent on a case-by-case basis or a general authorization with an obligation to inform regarding changes.
Is data processed outside the EEA? For transfers outside the European Economic Area, additional safeguards, such as model contract clauses, are required.
How sensitive is the data? For special categories (health, BSN) or large volumes, stricter security requirements apply and possibly a DPIA.
Who is liable in the event of a data breach? Establish the apportionment of liability and any indemnification, aligned with the underlying main agreement.
Clauses and provisions

Which elements belong in a data processing agreement?

Pursuant to Article 28, paragraph 3 of the GDPR, a data processing agreement must contain a number of mandatory topics. The components below together form a comprehensive agreement between you and your processor.

Provision Relevant to Legal point of attention
Subject and duration of processing Always mandatory Describe which data is processed, for what reason, and for how long, so that the scope is established.
Nature, purpose and categories of data Always mandatory Document which types of personal data and data subjects are involved and for what purpose they are processed.
Instruction authority of the controller Always mandatory The processor may act solely on your written instructions and not for its own purposes.
Security measures Always mandatory Concrete technical and organizational measures pursuant to Article 32 of the GDPR, appropriate to the risk.
Enabling sub-processors In the event of outsourcing to third parties Rule on whether and under what conditions the processor may use sub-processors and what consent is required.
Data breach notification obligation Always mandatory Agreements regarding the timeframe and manner in which the processor informs you of a breach, so that you meet the 72-hour deadline.
Assistance with the rights of data subjects Always mandatory The processor assists you with requests for access, correction, or deletion and with conducting a DPIA.
Return or destruction after end Always mandatory Upon termination, data will be returned or deleted and existing copies removed, unless a retention obligation applies.
Use in practice

How do you use this document correctly?

A data processing agreement is not a formality that you sign once and put away. Use the document in such a way that it also works in practice.

Situation What should you do? Point of attention
Before the start of the collaboration Conclude the agreement before the processor gains access to personal data. Without a valid agreement, the processing is unlawful from day one.
When drawing Check whether the description of data and purposes corresponds to reality. A description that is too general or incorrect renders the agreements unusable in practice.
During the term Maintain an up-to-date overview of enabled sub-processors. You remain ultimately responsible and must know where your data is processed.
Upon termination Ensure the return or demonstrable destruction of the data. This prevents data from remaining with a former processor unnecessarily.
Common mistakes

Common mistakes

Data processing agreements often go wrong on the same points. By avoiding the mistakes below, you prevent unnecessary risks and disputes.

Wrong Consequence Better approach
Do not enter into an agreement with a service provider Violation of Article 28 GDPR and risk of a fine. Conclude a data processing agreement with every party that processes personal data on your behalf.
Blindly copying the supplier's standard text The agreements do not align with your situation and do not protect you sufficiently. Critically evaluate the text and adapt it to your role and data.
Do not arrange sub-processors No visibility into and no control over parties further down the chain. Include a clear provision regarding consent and the duty to inform for sub-processors.
Describe security too vaguely In the event of an incident, it is unclear which measures were agreed upon. Describe concrete technical and organizational measures in accordance with Article 32 of the GDPR.
Entering into a data processing agreement while the party is not a data processor Incorrect division of roles and wrong obligations. First determine whether the party is actually processing for you or is responsible itself.
Risk profile

What is your situation and what do you pay attention to?

Which points of attention carry the most weight for you depends on your specific situation. Below you will find common cases with the corresponding focus.

Risk profile Example Focus in the document
Enabling a cloud service You use SaaS or hosting services where data is stored elsewhere. Pay attention to the location of storage, sub-processors, and transfers outside the EEA.
Processing of sensitive data This concerns health, financial, or other special data. Strict security requirements and potentially a mandatory Data Protection Impact Assessment.
Many small suppliers You work with various service providers, each of whom processes limited data. Maintain an overview and ensure that an agreement has been concluded with every party.
You are the processor yourself You engage a client to process data. Document that you are acting only on instruction and limit your liability where possible.
Additional documents

When is this document not enough?

A data processing agreement covers the relationship with a processor, but not every situation regarding collaboration and data. You will need additional documents in the following cases.

Situation Supplementary document Why
Situation Confidentiality Agreement In addition to privacy, you also want to protect confidential business information that does not constitute personal data.
You will collaborate on a structural basis Cooperation Agreement Document the broader commercial and operational agreements of the collaboration.
A conflict arises regarding compliance Legal assistance In the event of disputes or a data breach, you need legal assistance that goes beyond the document itself.
Explanation of this document

Drafting a Data Processing Agreement, why?

Not every entrepreneur knows exactly what a data processing agreement is, when you need one, and which risks they must cover. That is why we explain below what this document entails, what you should look out for, and why customized legal solutions are important.

What is a data processing agreement?
A data processing agreement is the agreement that must be concluded pursuant to Article 28(3) of the GDPR between a controller—the party that determines the purpose and means of data processing—and a processor—the party that processes personal data on behalf of the controller. The data processing agreement sets out the instructions for processing, the security requirements, the duty of confidentiality of the processor's employees, the arrangement for sub-processors, the obligation to report data breaches, the obligations regarding audits and DPIAs, and the return or deletion of personal data at the end of the assignment. Our lawyers will draft a data processing agreement for you that fully complies with the requirements of Article 28 of the GDPR, correctly describes the sub-processor arrangement, clearly formulates the data breach notification obligation, and adequately protects your liability position as a controller or processor.
When do you need a data processing agreement?
A data processing agreement is mandatory whenever a data controller has personal data processed by a processor. A processor is a party that processes personal data on behalf of and for the benefit of the data controller, without determining the purposes of the processing itself. Examples include: a payroll administration office, a cloud software provider, a marketing agency that manages email addresses, or a security company that provides CCTV surveillance. You do not need a data processing agreement if the other party is the data controller for its own purposes. Our lawyers will assess for you with which suppliers a data processing agreement is mandatory.
How do you arrange the sub-processor arrangement in the processor agreement?
The sub-processor arrangement is one of the most negotiated parts of the processor agreement. The processor may engage sub-processors only with the prior written consent of the controller — specifically per sub-processor, or via generic consent with an objection option for new sub-processors. The processor remains fully liable for the actions of its sub-processors and must impose the same GDPR obligations on its sub-processors. Our lawyers draft a sub-processor clause that protects your position as the controller.
How does it work at MKBjuristen?
After a brief intake, our lawyers draft a data processing agreement that fully complies with Article 28 of the GDPR, correctly describes the sub-processor arrangement, clearly formulates the data breach notification obligation, and adequately protects your liability position.
Are you unsure whether your document is legally correct? We would be happy to assess the sensible course of action: drafting, reviewing, or amending.
Request a quote

Why not use a standard document?

A standard document often seems like a quick solution, but usually does not fully align with your company, agreements, risks, and way of working. Our legal experts draft documents that fit your situation.

Standard document
SME Lawyers
Not tailored to your business
Tailored to your company, industry, and working methods
No control over your specific situation
Consultation with a lawyer and assessment of your risks
Possibly outdated or incomplete
Verification of current and practical provisions
No personal explanation
Explanation regarding the use of the document

A standard document seems cheap, until it doesn't fit your situation properly. That is why we provide custom legal solutions tailored to your business.

Tailored solutions for each privacy relationship

Not every processing activity is the same. Therefore, we do not draft generic data processing agreements, but tailor them to the GDPR role, type of data, systems, and risk.

SaaS and platforms

Attention to user data, hosting, support, sub-processors, uptime, security, and exit.

IT management

Attention to system access, logs, authorizations, data breaches, backups, and confidentiality.

Marketing

Focus on leads, email, tracking, analytics, subtools, consent, and retention periods.

Administration and payroll

Focus on financial data, HR data, BSN, retention obligations, access, and security.

Care and sensitive data

Attention to special data, logging, confidentiality, authorizations, and reporting procedures.

International tools

Attention to sub-processors, transfers, countries, safeguards, and contractual control.


A data processing agreement must make GDPR roles and data processing concrete. Therefore, we look at instructions, data categories, security, sub-processors, data breaches, audits, transfer, deletion, and liability.

Common mistakes in data processing agreements

Data processing agreements often go wrong because parties use a template without analyzing the actual processing.

  • Misclassifying processor and controller
  • Describe personal data, data subjects, and processing purposes too vaguely
  • Failure to make security measures concrete or verifiable
  • Forgetting subprocessors, international transfers, and cloud tools
  • Arranging data breach procedures and notification deadlines in an insufficiently practical manner
  • Incorporating audit law too broadly or too narrowly
  • Do not arrange data export, deletion, and backups at end
  • Do not align liability with main agreement

Draft your data processing agreement properly and prevent unnecessary problems in the future. Good agreements prevent disputes regarding GDPR roles, security, data breaches, sub-processors, audits, and data deletion.

What is a data processing agreement?

An agreement between a controller and a processor containing arrangements regarding the processing of personal data on behalf of the controller.

When is a data processing agreement necessary?

When a party processes personal data on behalf of another party and does not itself determine the purpose and means of the processing.

Is every supplier a processor?

No. Sometimes a supplier is an independent controller, or the parties are jointly responsible.

What should be included in a data processing agreement?

Including instructions, data categories, security, confidentiality, sub-processors, data breaches, audits, transfer and deletion.

Can MKB Juristen review an existing data processing agreement?

Yes. We check, among other things, GDPR roles, security, sub-processors, data breaches, transfer, exit, and liability.

Contact us

Annelore Hendriks

Want to know more about our services?
Then contact our specialists.

Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation