Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
    • House Debates Stopgap Funding Bill That Would Revive Cyber Threat Info-Sharing Law
    • Democratic Governors Urged to Block Data-Sharing With ICE
    • EU Privacy Advocates Decry Proposed Changes to GDPR
    • Overview of Data Broker Opt-Out System Provided by California Privacy Agency
    • Recommendations for Data Processing Agreements Offered in Netherlands
    • U.K. Parliament Readies Bill to Update Cybersecurity Law
    • U.K.’s Information Commissioner Aims to Raise Public Sector Data Protection Standards
    • Warnings Issued to Dutch Websites With Noncompliant Cookie Banners
  • Articles
  • Articles

    Cybersecurity Policy Report, Recommendations for Data Processing Agreements Offered in Netherlands, (Nov 12, 2025)

    By R. Jason Howard, J.D.

    The Dutch data protection authority, Autoriteit Persoonsgegevens (AP), has published recommendations for strong data processing agreements between organizations that could improve cyber incident response and prevent some cyber attacks.

    Data processing ...

    By R. Jason Howard, J.D.

    The Dutch data protection authority, Autoriteit Persoonsgegevens (AP), has published recommendations for strong data processing agreements between organizations that could improve cyber incident response and prevent some cyber attacks.

    Data processing agreements between organizations and service providers are required for the sharing and use of personal data, the AP noted in a news release.

    Because service providers often work for multiple organizations, they are attractive targets for cyber attacks, the AP said. Following an investigation of five major cyber attacks on service providers that collectively affected more than 1,250 organizations in the Netherlands, the AP determined that the “lack of proper data processing agreements left the organizations involved with little control over preventing and handling the cyberattack,” it said.

    Based on its investigation, the AP offered the following three recommendations for organizations and service providers to limit the damage from cyber attacks:

    1. Data processing agreements should be as concrete as possible and should go beyond simply reiterating the requirements of the European Union’s General Data Protection Regulation;

    2. Organizations should maintain control over the entire supply chain because they are responsible for their customers’ personal data even if services are outsourced to one or more service providers; and

    3. Organizations should prioritize drafting and maintaining data processing agreements and regularly review agreements to ensure they remain relevant in practice.

    News: InternationalLegislation DataSecurity

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use