Almost every company operating in the Netherlands outsources something that touches personal data: payroll, hosting, CRM, marketing, recruitment, support. Where a supplier processes personal data on your instructions, art. 28 GDPR requires a written contract, in Dutch a verwerkersovereenkomst. This guide covers when it is required, what it must contain, how the Dutch supervisory authority approaches it, and how the clauses that matter are negotiated.
When a processing agreement is required, and when it is not
It is required in one situation only: where one party processes personal data on behalf of another. The party deciding why and, in essence, how the data are processed is the controller; the party acting on its instructions is the processor. The duty runs down the chain, so a processor engaging a sub-processor must contract equivalently with it. None is needed where the parties are independent controllers each pursuing their own purposes, where they are joint controllers, which calls for an arrangement under art. 26 GDPR instead, or where no personal data are involved.
Signing one with a party that is in fact an independent controller is not harmless: it misstates who is accountable and creates an illusion of instruction neither party can honour. The mirror error is as common, where a supplier acting on its own account accepts instruction-only terms it cannot comply with.
Controller or processor: how the distinction is actually assessed
The assessment is functional, not formal: what the contract calls the parties is evidence, not the answer. The reference point is the EDPB’s Guidelines 07/2020 on controller and processor, whose final version was adopted on 7 July 2021.
Purposes and essential means
The controller determines the purposes and the essential means: which categories of data are processed, about whom, for how long, and to whom they are disclosed. Those decisions are tied to lawfulness and necessity and cannot be delegated. Non-essential means, the implementation detail, may be left to the supplier: which software it runs and how it engineers its controls.
An organisation can therefore be a controller although it never touches the data. In its judgment of 5 December 2023 in case C-683/21 (Nacionalinis visuomenės sveikatos centras), the Court of Justice held that an entity determining the purposes and means of processing carried out through an app it had commissioned was a controller, and that joint controllership can arise from converging decisions without any formal arrangement. Conversely, a processor going beyond instructions to process for its own purposes is treated by art. 28 GDPR as a controller for that processing.
The situations that trip companies up
- Payroll bureaux. Where the bureau enters the data you supply and produces payslips, it is a processor. Where the engagement extends to independent advice and compliance checks in the firm’s own judgement, the Dutch professional bodies’ guidance of 1 October 2019 for accountants, tax advisers and payroll professionals treats it as a controller.
- Accountants and tax advisers. Statutory audit, compilation and tax return work are performed under the firm’s own professional and statutory duties, with independent judgement. That points to controller status, and a processing agreement is then the wrong document.
- Marketing agencies. An agency running a campaign against your customer list is a processor. One that builds or enriches audiences, or runs ad-tech in which the platform sets the parameters, has purposes of its own, and joint controllership with the platform is a live possibility.
- IT suppliers, hosting and SaaS. Normally processors, but check the clause reserving the right to use “aggregated” or “usage” data for service improvement, benchmarking or model training. To the extent that involves personal data, it is the supplier’s own purpose and it is a controller for it.
- Recruiters. An agency maintaining its own candidate database is controller of it. Processing named applicants for your vacancy is usually a mix of two controllers with limited processing on instruction in between.
Joint controllership and the arrangement it requires instead
Where two parties jointly determine purposes and means, whether by common decision or by decisions that converge and are inextricably linked, art. 26 GDPR requires an arrangement rather than a processing agreement. It must determine transparently who answers data subjects and who handles transparency information, security, breach notification, impact assessments and transfers. Its essence must be made available to data subjects, who may exercise rights against either party however the parties have carved things up, and it binds neither the Autoriteit Persoonsgegevens nor a court.
The mandatory content under art. 28 GDPR
The contract must be in writing, including electronic form, and binding on the processor. Art. 28 GDPR sets a fixed list, and the EDPB is explicit that reciting the regulation back at itself is not enough.
| Required element | What the contract must set out |
|---|---|
| Description of the processing | Subject matter, duration, nature and purpose, type of data, categories of data subjects, and the controller’s rights and obligations. Usually annexed, and usually too generic |
| Documented instructions | Processing only on the controller’s documented instructions, including as to transfers. Watch for “as otherwise permitted by the agreement”, which swallows the rule |
| Confidentiality | Authorised persons bound by confidentiality, contractually or by statute; it should reach sub-processor staff too |
| Security | The measures required under art. 32 GDPR. A cross-reference is worthless: annex the measures |
| Sub-processors | The conditions for engaging another processor, and the authorisation regime |
| Data subject rights | Appropriate measures to help the controller answer requests; fix deadlines and confirm it is within the fee |
| Security, breaches, impact assessments | Assistance with security, notification to the authority and to data subjects, impact assessments and prior consultation |
| Deletion or return | At the controller’s choice, deletion or return at the end of the services, and deletion of copies unless storage is legally required |
| Compliance information and audits | The information needed to demonstrate compliance, and allowing and contributing to audits |
| Unlawful instructions | The processor informs the controller if an instruction infringes data protection law |
Sub-processors and the authorisation regime
A processor may not engage a sub-processor without the controller’s authorisation. Specific prior authorisation approves each one individually, which works for a small stable chain but not for a large cloud service. General written authorisation lets the processor add or replace sub-processors provided it informs the controller of intended changes and allows it to object.
Nearly every standard supplier agreement offers general authorisation, a list and a notice period, so the negotiation is about what that notice is worth: a route that does not depend on you monitoring a web page, a period long enough to act on, and a stated consequence if you object, realistically termination without penalty. Either way the processor must impose the same obligations back-to-back and remains liable for the sub-processor. In Opinion 22/2024 of 9 October 2024 the EDPB confirmed that accountability extends to the whole chain: the controller should be able to identify every sub-processor and satisfy itself that the safeguards hold throughout.
The security obligation, made concrete
“The processor shall implement appropriate technical and organisational measures in accordance with art. 32 GDPR” is a platitude: it tells you nothing and proves nothing. A usable annex states encryption in transit and at rest and how keys are managed; access control, including joiner-mover-leaver processes and multi-factor authentication; what is logged and for how long; backup frequency and tested restoration; patching and penetration testing timeframes; the certifications relied on, with their scope; and where data are stored and accessed, support staff included.
This matters evidentially. In its judgment of 14 December 2023 in case C-340/21 (Natsionalna agentsia za prihodite), the Court of Justice held that a security incident does not by itself establish that the measures were inadequate, but that the controller bears the burden of showing they were appropriate. A dated annex is that evidence; a cross-reference is not.
Assistance with data subject rights and with breach notification
Both obligations are deadline-driven, and the deadlines belong to the controller. On data subject rights, the controller must respond within one month, so “reasonable assistance” without a timeframe leaves you to absorb the delay. Fix it: any request the supplier receives is forwarded within a stated number of working days and never answered by it; a complete extract is produced in a usable format within five to ten working days; and this sits within the fee rather than triggering an invoice.
On breaches, the controller must notify the Autoriteit Persoonsgegevens without undue delay and, where feasible, within 72 hours of becoming aware, under art. 33 GDPR. Make the processor’s duty concrete: notification within 24 hours, to a named contact with an out-of-hours route, with a defined minimum content set even where facts are incomplete; cooperation with forensics; and a bar on notifying the authority or data subjects without your approval. In-scope organisations also report incidents to their CSIRT under the Dutch Cyberbeveiligingswet, which implements the NIS2 Directive and has applied since 15 August 2026.
Audit rights and how they are negotiated
Art. 28 GDPR requires the processor both to make available the information needed to demonstrate compliance and to allow and contribute to audits, including inspections, by the controller or an auditor it mandates. A clause offering only “our latest certification” falls short. The compromise most Dutch negotiations reach: an annual assurance report as of right, with its scope document; a documented audit once a year, plus a further audit after a breach affecting your data or at a supervisory authority’s request; thirty days’ notice; scope confined to your services; an auditor who is not a competitor; and costs borne by you unless material non-compliance is found.
Return or deletion at the end
The choice is the controller’s, and the contract should say so rather than reserving it to the supplier. Specify the export format, the deadline, commonly thirty days from termination, written confirmation of deletion, and how backups are handled, which realistically means the data stay in a documented cycle, protected and unused, until overwritten. Agree exit assistance and rates in advance, and exclude any right to withhold data over disputed fees.
Liability, indemnities and the GDPR’s own liability regime
Art. 82 GDPR gives a data subject a right to compensation for material and non-material damage. A controller is liable for damage caused by processing that infringes the regulation; a processor is liable where it has not complied with obligations directed specifically at processors, or has acted outside or contrary to lawful instructions. Where both are involved in the same processing, each can be held liable for the entire damage, with recourse afterwards. That exposure cannot be contracted away; the contract allocates the internal share. Fines are separate: infringements of art. 28 GDPR fall in the lower bracket in art. 83 GDPR.
- Standard terms cap liability at a multiple of fees and exclude “indirect and consequential loss”. If regulatory fines, notification and forensic costs and compensation to data subjects fall inside that exclusion, the indemnity is decorative: list them as recoverable direct loss.
- Seek a carve-out, or an enhanced cap, for breach of the processing agreement, breach of confidentiality, and deliberate or reckless breach.
- A fine imposed on you cannot be passed on as a fine, but can be recovered as loss under a properly drafted indemnity. Dutch collective actions under the WAMCA regime make aggregated claims a realistic exposure, which argues against a derisory cap.
International transfers, standard contractual clauses and the position now
If the processor, its sub-processors or its support staff can access the data from outside the EEA, Chapter V of the GDPR applies on top of art. 28. Remote access counts, and so does a support desk abroad.
Absent an adequacy decision under art. 45 GDPR, the usual tool is the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, under art. 46 GDPR. Two points are regularly missed. The modules covering controller-to-processor and processor-to-sub-processor transfers also satisfy the art. 28 GDPR requirements, so a separate processing agreement is not needed for that leg, although many contracts stack both. And after the Court of Justice’s judgment of 16 July 2020 in case C-311/18 (Schrems II), signing is not the end of it: the parties must assess whether the law and practice of the destination country prevent the importer from complying, and add supplementary measures where they do. Document that assessment; the EDPB’s Recommendations 01/2020, adopted on 18 June 2021, still set the approach.
For the United States, the Commission’s adequacy decision of 10 July 2023 for the EU-US Data Privacy Framework remains in force, but it helps only where the specific recipient is actively self-certified for the relevant data categories, so verify the certification. It survived its first challenge: the General Court dismissed the action by judgment of 3 September 2025 in case T-553/23 (Latombe v Commission). An appeal was lodged on 31 October 2025 as case C-703/25 P and the Court of Justice had not closed the case as at the date of this page in 2026; the adequacy decision has meanwhile been neither suspended nor amended. Do not let it become a single point of failure: keep the clauses and a documented assessment as a fallback, and treat the pending appeal as a reason to have one rather than a reason to wait. The Autoriteit Persoonsgegevens fined Uber €290 million by decision of 22 July 2024 for transferring drivers’ data to the United States without an appropriate transfer tool after it had stopped using the clauses; Uber stated that it intended to object, the AP has published no decision on that objection, and the fine should therefore be read as a statement of the regulator’s position rather than a settled precedent.
One gap in the toolkit is still open. The Commission has said it is preparing a further set of standard contractual clauses for importers outside the EU whose processing is itself directly subject to the GDPR under art. 3 — the situation in which the 2021 clauses do not sit comfortably. Those clauses had not been adopted as at the date of this page in 2026, so for that configuration the assessment and the safeguards have to be built into the contract by hand.
Are the Commission’s controller-processor clauses compulsory?
No. Commission Implementing Decision (EU) 2021/915 of 4 June 2021 provides standard contractual clauses between controllers and processors for use within the EEA, but using them is optional: parties may negotiate their own contract provided it contains everything art. 28 GDPR requires. The clauses can sit inside a wider contract with additional, non-contradictory terms, but may not themselves be modified, so customisation happens in the annexes. Bespoke agreements and sector models remain the Dutch norm, which is acceptable provided the substance is there.
Enforcement by the Autoriteit Persoonsgegevens
The AP has examined this directly. It reviewed the processing agreements used by 31 private-sector organisations across trade, healthcare, media, leisure and energy, publishing its findings in 2020 under the heading that “the” processing agreement does not exist. It found agreements doing little more than quoting the regulation, security language noting that a policy existed without saying what it required, and agreements still drafted under the old Dutch data protection statute.
In an investigation, expect the AP to work from your record of processing activities to the contracts with the suppliers named in it, then to the security annex, sub-processor list and transfer documentation, and then to evidence that you did something with them: an unread assurance report is not oversight. Fault matters too, since in case C-683/21 the Court of Justice confirmed that a fine requires intentional or negligent infringement. The AP’s strategic focus for 2026 to 2028 covers mass surveillance, artificial intelligence and digital resilience, the last expressly including supply chain security.
A checklist for reviewing a supplier’s standard processing agreement
- Are the roles right? If the supplier is an independent controller, do not sign a processing agreement at all.
- Is the processing description completed, or an empty annex, and does anything permit processing for the supplier’s own improvement, analytics or model training?
- Are the security measures annexed and specific, with named certifications and their scope?
- Is the sub-processor list available, is notice pushed to you, does objection have a consequence, and are sub-processors bound back-to-back?
- Is breach notification within a fixed short period, and is the supplier barred from notifying the authority itself?
- Are data subject request deadlines fixed and within the fee, and is there a genuine audit right rather than only a certificate?
- Does deletion or return sit at your choice, with format, deadline and backup treatment?
- Where are the data stored and accessed, and is the right transfer tool in place for every leg?
- Do the cap and the indirect loss exclusion leave the indemnity with real content, and is there an internal owner and a review date?
Is a processing agreement required between two group companies?
Yes, if they are separate legal entities and one processes personal data on behalf of the other. Belonging to the same group makes no difference. Groups commonly use one intra-group framework covering all entities, with schedules per service. Where entities process for their own purposes, they are separate controllers and a different instrument is appropriate.
Does the agreement have to be in Dutch?
No. There is no language requirement, and English-language agreements are entirely normal in Dutch practice. If operational teams or a works council will read it, a Dutch version helps, and where both exist you should state which prevails. The Autoriteit Persoonsgegevens accepts English in most correspondence, though not invariably.
Our supplier refuses to negotiate its standard terms. What are our options?
You remain accountable regardless. Assess whether the terms actually meet art. 28 GDPR; many large providers’ terms do, and the real gaps are commercial ones such as caps and audit scope. Document the assessment and the residual risk, seek concessions on the annexes rather than the body, and record the decision.
Do we need a separate processing agreement if we have signed the standard contractual clauses?
Usually not for that relationship. The transfer clauses adopted in 2021 for controller-to-processor and processor-to-sub-processor transfers were designed to cover the art. 28 GDPR requirements too, and stacking a separate agreement on top creates conflicting terms. If you keep both, include an order of precedence and check the annexes are consistent.
What happens if we have no processing agreement at all?
The absence is itself an infringement of art. 28 GDPR by both parties, punishable under the lower fine bracket in art. 83 GDPR, and among the first things a supervisory authority checks. It also leaves you without contractual footing on security, breach notification, audits and deletion, and without recourse if the supplier causes damage you must compensate.

