Create a bespoke document in minutes, Â or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Data Transfer Addendum
"I need a Data Transfer Addendum under Dutch law for transferring medical research data from our Amsterdam hospital to a cloud service provider in Germany, with special attention to sensitive data handling and sub-processor requirements."
1. Parties: Identification of the data exporter and data importer, including their roles (controller/processor)
2. Background: Context of the addendum, reference to main agreement, and purpose of the data transfer arrangement
3. Definitions: Key terms used in the addendum, including those from GDPR and main agreement
4. Scope and Purpose: Details of the data transfers covered, including categories of data subjects and personal data
5. Roles and Responsibilities: Clear designation of parties' roles under GDPR and specific obligations of each party
6. Transfer Mechanisms: Legal basis for transfers and applicable transfer mechanisms (e.g., SCCs, adequacy decisions)
7. Data Security: Technical and organizational measures for ensuring data security during transfers
8. Sub-processing: Conditions and requirements for engaging sub-processors
9. Data Subject Rights: Procedures for handling data subject requests and ensuring their rights
10. Data Breach Notification: Procedures and timeframes for reporting data breaches
11. Audit Rights: Provisions for monitoring compliance and conducting audits
12. Term and Termination: Duration of the addendum and conditions for termination
13. Return or Deletion of Data: Obligations regarding data upon termination of services
14. Governing Law and Jurisdiction: Confirmation of Dutch law application and jurisdiction
1. Special Categories of Data: Additional safeguards for sensitive data - include when special category data is processed
2. Cross-Border Transfers Outside EEA: Specific provisions for transfers to non-adequate countries - include when transfers outside EEA are contemplated
3. Data Protection Impact Assessment: Reference to and results of any DPIA - include when high-risk processing is involved
4. Specific Technical Requirements: Detailed technical specifications for transfers - include when specific technical methods are mandated
5. BCR Integration: Integration with Binding Corporate Rules - include when one party uses BCRs
6. Industry-Specific Requirements: Additional requirements for specific sectors - include for regulated industries
7. Joint Controller Arrangements: Specific provisions for joint controller scenarios - include when parties are joint controllers
1. Schedule 1 - Details of Processing: Detailed description of processing activities, categories of data, purposes, etc.
2. Schedule 2 - Technical and Organizational Measures: Comprehensive description of security measures implemented
3. Schedule 3 - Approved Sub-processors: List of approved sub-processors and their processing activities
4. Schedule 4 - Transfer Mechanisms: Copies of relevant SCCs or other transfer mechanism documentation
5. Schedule 5 - Contact Points: List of key contacts for data protection matters at each party
6. Appendix A - Data Processing Details: Specific details about the processing operations, frequency, and nature
7. Appendix B - Security Controls: Detailed security controls and compliance requirements
Authors
Technology
Healthcare
Financial Services
E-commerce
Professional Services
Manufacturing
Education
Telecommunications
Retail
Insurance
Pharmaceutical
Logistics
Marketing Services
Cloud Services
Research and Development
Legal
Compliance
Information Security
IT
Privacy
Risk Management
Data Protection
Information Governance
Procurement
Operations
Technology
Information Management
Data Protection Officer
Privacy Counsel
Legal Counsel
Compliance Manager
Information Security Officer
Privacy Manager
Chief Technology Officer
IT Security Manager
Data Privacy Specialist
Contract Manager
Risk Manager
Chief Information Security Officer
Chief Legal Officer
Privacy Operations Manager
Data Governance Manager
Find the exact document you need
Intra Group Data Sharing Agreement
Dutch law-governed agreement for regulated data sharing between companies within the same corporate group, ensuring GDPR compliance and efficient data management.
Intercompany Data Transfer Agreement
Dutch law-governed agreement for regulated data transfers between group companies, ensuring GDPR compliance and proper data protection measures.
Data Transfer Agreement Clinical Trial
Dutch-law governed Data Transfer Agreement for clinical trials, ensuring GDPR compliance and proper handling of clinical research data.
Data Transfer Addendum
A Dutch law-governed addendum establishing terms for GDPR-compliant personal data transfers between organizations.
Personal Data Transfer Agreement
Dutch law-governed agreement for regulated transfer of personal data between parties, ensuring GDPR compliance and data protection safeguards.
Download our whitepaper on the future of AI in Legal
³Ò±ð²Ô¾±±ð’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; ³Ò±ð²Ô¾±±ð’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our for more details and real-time security updates.
Read our Privacy Policy.