Cybersecurity Policy Report, Recommendations for Data Processing Agreements Offered in Netherlands, (Nov 12, 2025)
The Dutch data protection authority, Autoriteit Persoonsgegevens (AP), has published recommendations for strong data processing agreements between organizations that could improve cyber incident response and prevent some cyber attacks.
Data processing agreements between organizations and service providers are required for the sharing and use of personal data, the AP noted in a news release.
Because service providers often work for multiple organizations, they are attractive targets for cyber attacks, the AP said. Following an investigation of five major cyber attacks on service providers that collectively affected more than 1,250 organizations in the Netherlands, the AP determined that the “lack of proper data processing agreements left the organizations involved with little control over preventing and handling the cyberattack,” it said.
Based on its investigation, the AP offered the following three recommendations for organizations and service providers to limit the damage from cyber attacks:
Data processing agreements should be as concrete as possible and should go beyond simply reiterating the requirements of the European Union’s General Data Protection Regulation;
Organizations should maintain control over the entire supply chain because they are responsible for their customers’ personal data even if services are outsourced to one or more service providers; and
Organizations should prioritize drafting and maintaining data processing agreements and regularly review agreements to ensure they remain relevant in practice.
News: InternationalLegislation DataSecurity