Create a bespoke document in minutes, Â or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Controller To Controller Agreement
"I need a Controller to Controller Agreement governed by Dutch law for a data sharing arrangement between our medical research institute and a pharmaceutical company, with specific provisions for handling sensitive health data and research results starting from March 2025."
1. Parties: Identification of the two data controllers entering into the agreement, including full legal names, registration numbers, and registered addresses
2. Background: Context of the data sharing arrangement, purpose of the agreement, and the relationship between the parties
3. Definitions: Definitions of key terms used in the agreement, including GDPR-specific terminology
4. Purpose and Scope: Detailed description of the data sharing purpose, categories of data subjects and personal data involved
5. Roles and Responsibilities: Clear delineation of each controller's obligations and responsibilities in the data sharing arrangement
6. Legal Basis for Processing: Specification of the legal grounds under GDPR Article 6 for the data processing activities
7. Data Protection Principles: Commitment to GDPR principles including lawfulness, fairness, transparency, purpose limitation, and data minimization
8. Security Measures: Required technical and organizational measures to ensure appropriate security of shared personal data
9. Data Subject Rights: Procedures for handling data subject requests and ensuring data subject rights are respected
10. Personal Data Breaches: Notification requirements and procedures in case of data breaches
11. Confidentiality: Obligations regarding confidentiality of shared personal data
12. Term and Termination: Duration of the agreement and conditions for termination
13. Governing Law and Jurisdiction: Specification of Dutch law as governing law and jurisdiction for disputes
1. International Transfers: Required when personal data will be transferred outside the EEA, including appropriate safeguards and SCCs
2. Joint Processing Activities: Needed when certain processing activities are conducted jointly by both controllers
3. Audit Rights: Optional section granting mutual rights to audit compliance with the agreement
4. Insurance: Requirements for maintaining specific insurance coverage for data protection liabilities
5. Sub-processing: Rules regarding the appointment of processors by either controller
6. Costs and Fees: Required when there are financial arrangements related to the data sharing
7. Force Majeure: Optional provisions for handling circumstances beyond parties' control
8. Assignment and Subcontracting: Rules about transferring rights under the agreement or subcontracting obligations
1. Schedule 1 - Categories of Personal Data: Detailed list of personal data categories being shared between the controllers
2. Schedule 2 - Technical and Organizational Measures: Specific security measures implemented by both parties
3. Schedule 3 - Transfer Mechanisms: Details of transfer mechanisms used for international data transfers if applicable
4. Schedule 4 - Contact Points: List of key contacts for operational, technical, and data protection matters
5. Schedule 5 - Processing Activities: Detailed description of processing activities carried out by each controller
6. Appendix A - Data Breach Response Plan: Detailed procedures for handling and reporting data breaches
7. Appendix B - Standard Forms: Templates for regular communications, reports, or notices between parties
Authors
Financial Services
Healthcare
Technology
E-commerce
Professional Services
Education
Insurance
Telecommunications
Research and Development
Marketing and Advertising
Government and Public Sector
Manufacturing
Retail
Consulting
Transportation and Logistics
Legal
Compliance
Information Security
Privacy
Risk Management
Information Technology
Operations
Data Management
Corporate Governance
Procurement
Business Development
Data Protection Officer
Privacy Officer
Legal Counsel
Compliance Manager
Information Security Manager
Chief Privacy Officer
Chief Legal Officer
Chief Information Security Officer
Risk Manager
IT Director
Chief Technology Officer
Operations Manager
Project Manager
Business Development Manager
Contract Manager
Find the exact document you need
International Data Transfer Addendum
Dutch law-governed International Data Transfer Addendum for GDPR-compliant personal data transfers from the Netherlands/EU to non-EEA countries.
Intra Group Data Processing Agreement
Dutch law-governed data processing agreement for intra-group personal data transfers and processing, ensuring GDPR compliance within corporate groups.
Controller To Controller Agreement
A Dutch law-governed agreement between two data controllers establishing terms for compliant personal data sharing under GDPR and UAVG.
Product Development Non Disclosure Agreement
Dutch law-governed NDA for protecting confidential information in product development activities, including technical specifications and intellectual property.
Data Processing Contract
Dutch law-governed Data Processing Contract establishing GDPR-compliant terms between controller and processor.
Joint Controller Agreement
A Dutch law-governed agreement establishing responsibilities and obligations between joint controllers under GDPR and UAVG for shared data processing activities.
Dpia Agreement
A Dutch law agreement establishing the framework for conducting Data Protection Impact Assessments (DPIAs) in compliance with GDPR and local privacy regulations.
Data Processing Addendum
A Dutch law-governed agreement establishing GDPR-compliant terms for personal data processing between a controller and processor.
Data Agreement
A Dutch law-governed agreement establishing terms for data processing and sharing, ensuring compliance with Dutch and EU data protection regulations.
Data Addendum
A Dutch law-governed supplementary agreement that adds GDPR and UAVG-compliant data protection terms to an existing contract.
Third Party Processor Agreement
A Dutch law-governed agreement establishing terms for third-party processing of personal data under GDPR and UAVG requirements.
Intercompany Data Processing Agreement
A Dutch law-governed agreement regulating personal data processing between affiliated companies within the same corporate group, ensuring GDPR compliance.
Third Party Data Processing Agreement
Dutch law-governed agreement establishing GDPR-compliant terms for third-party processing of personal data, aligned with both EU and Dutch data protection requirements.
Controller Processor Agreement
A Dutch law-governed agreement establishing GDPR-compliant terms for personal data processing between controller and processor.
Order Processing Agreement
A Dutch-law governed agreement between a data controller and processor establishing terms for personal data processing under GDPR and Dutch UAVG requirements.
Affiliate Addendum
Dutch law-governed addendum for affiliate marketing arrangements, outlining partnership terms, commissions, and compliance requirements.
Sub Processing Agreement
Dutch law-governed agreement between a processor and sub-processor for GDPR-compliant data processing activities.
International Data Transfer Agreement
Dutch law-governed agreement for international personal data transfers, incorporating EU Standard Contractual Clauses and GDPR compliance measures.
Data Protection Addendum
Dutch law-governed data protection addendum establishing GDPR-compliant terms for personal data processing between controllers and processors.
Download our whitepaper on the future of AI in Legal
³Ò±ð²Ô¾±±ð’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; ³Ò±ð²Ô¾±±ð’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our for more details and real-time security updates.
Read our Privacy Policy.