Since January 2016, parties that enter into an outsourcing process in which personal data are processed have to register a so-called Data Processing Agreement (DPA). This agreement arises from the Personal Data Protection Act (with the Data Compulsory Data Liability Act). In this processor agreement there is a so-called 'processor' and a 'responsible'.
In the case that you let Expansion do the service provision of your privacy-sensitive data, such as the digital management of your pension or personnel files, then Expansion is the ‘processor’ and you as a customer are the ‘responsible’. The Dutch Data Protection Authority (AP) has not only made the agreement obligatory as such: such a processor agreement, like between Expansion and you as our client, must also meet a number of strict requirements.
Processor agreement Expansion offers security for all parties
Formally, the responsibility for concluding the processor's contract lies with the owner of the data. Expansion offers its customers the opportunity to use a standard contract as a service. This agreement naturally complies with the requirements of the Dutch Data Protection Authority.
Together with you, we irrefutably determine who exactly can do what, how that process works and who is responsible for what. Then there is no longer any misunderstanding about this: with Expansion you are guaranteed of a reliable party that manages sensitive data in your order in a correct and verifiable manner.
At Expansion we understand the processes, bottlenecks and sensitivities around (the processing of) privacy-sensitive (digital) data and we offer our customers - literally in black and white - the certainty that everything is complete, controlled and according to the rules. It is no coincidence that we are the specialist in well thought-out solutions and services around digital document management for almost 30 years.
Requirements on the processors agreement
The processer agreement of Expansion is clear and meets all requirements that the Authority Personal Data demands on such an agreement, like:
- the agreement is specifically about data processing by Expansion as processor.
- The obligations that Expansion has to its customers, but also the other way round, are clearly recorded in the agreement: everything concerning the processing, the type of data, the purpose of the processing, the duration of the storage and the security measures taken are included.
- Expansion guarantees in the agreement with its customers that all fitting technical and organizational measures are taken to protect the data of our customers.
- The agreement says how you as our customer can verify the compliance of the guarantees that we as Expansion offer. That can also be an external expert party.
- In all our processor agreements it is stated explicitly that the employees of Expansion are bound by a confidentiality obligation.
- If there are any other parties active as processor in the cooperation, then there are also provisions included in the agreement about that.
For Expansion, these requirements are no more than a logical set of conditions for an effective, stable and reliable cooperation: clear and verifiable for everyone involved.
The goal of the processor agreement
The drafting of a processor agreement between Expansion and you as our customer has an underlying purpose. That goal is not so much to (only) comply with the laws and regulations. The real goal is that you are sure that Expansion handles your privacy-sensitive data in a confidential and reliable way. Without that certainty, you immediately run a business risk. Data could be lost or come to malicious, unauthorized persons or agencies. There could be data leaks. This can in all cases lead to large (immaterial and / or image) damage for your company.
Expansion guarantees that you have insight into all aspects of our cooperation with the processor agreement. You know where you stand; you know that Expansion will do everything to its abilities, technical and organizational, to run your data processing perfectly. And the good thing is, you can verify that, because at Expansion we value transparency. No covered conditions or hidden terms: we offer you clarity and guarantees.
Expansion takes its responsibility and shares with you the responsibility for an adequate and sound information management. A clear and workable processor agreement forms an essential part of this.
Would you like to know more about the processor agreement and/or make use of the service that Expansion offers in the form of a standard processor agreement?