Skip to main content

Data processing agreement

We Cookie First by Digital Data Solutions offer compliance solutions for websites concerning the use of cookies. Our software identifies cookies on your website(s) and helps website owners to execute cookies only if the correct permission or consent is given. If you decide to make use of our services, you pass along personal data (in the sense of the GDPR) of third parties (data subjects) to us. You are therefore under an obligation to conclude a data processing agreement with us. That is why this data processing agreement applies to our services.


Article 1 – Definitions

GDPR General Data Protection Regulation.
Data Subjects The persons of which personal data is collected on the basis of this data processing agreement; data subjects within the meaning of what is specified in the GDPR.
Agreement The underlying Data Processing Agreement, applicable between Parties.
Parties Processor and Controller referred to jointly.
personal data Data which can be used either directly or indirectly to identify a natural person, as intended in the GDPR.
Controller You, who as a user makes use of our services and therefore you supply us with personal data of Data subjects. As such, you are the Controller in the sense of the GDPR.
Processor We, Cookie First by Digital Data Solutions with the following address: Plantage Middenlaan 42a, 1018 DH Amsterdam, registered with the Chamber of Commmerce under the following number: 75762277, operating as a processor of personal data with which Controller supplies us.
Sub Processors Third parties, employed by Processor for the processing of personal data for the benefit of Controller.

Article 2 – Background

  1. Controller acts as a controller (also called a ‘data controller’), in the sense of the GDPR. This means that the purpose and the means of the processing of personal data are determined by Controller, and that Controller uses this data for its own personal purposes.
  2. Processor acts as a ‘processor’ in the sense of the GDPR. This means that Processor only processes the personal data supplied by Controller in accordance with Controller’s written instructions, as described in this Data Processing Agreement. Processor shall not process the data for its own personal purposes.

Article 3 – Execution of the processing

  1. In the execution of the assignment, Data Processor will handle the personal data in a careful manner and only process the personal data based on the assignment of Data Controller, in accordance with its written instructions and in accordance with this Agreement and the GDPR.
  2. Data Processor will not process the personal data for any other purpose than as determined by Data Controller. Data Processor has no control over the purpose and means of the processing of the personal data.
  3. Data Processor further guarantees that every person acting under its authority will process the personal data lawfully and in accordance with this Agreement and the GDPR.
  4. At the request of Data Controller, Data Processor will provide Data Controller with information about the (security) measures taken in order to comply with the obligations under the GDPR, this Agreement and other instructions from Data Controller.

Article 4 – Warranty Data Controller

Data Controller guarantees the processing of the personal data of the Data Subjects, as referred to in this Agreement, is not unlawful and does not violate the rights of others. Data Controller indemnifies Data Processor against all claims relating to this.

Article 5 – Transfer of personal data

  1. In principle, Processor only processes the personal data within the confines of the European Union and the countries that have been designated by the European Commission as countries offering an adequate level of protection.
  2. Processor shall only pass along personal data to countries for which no adequacy decision has been taken, if this is in accordance with the requirements of the GDPR. In case the consent of Data Subjects is required, Controller shall bear the responsibility for acquiring it.
  3. Processor shall notify Controller in advance of any processing in another country that is not included in paragraph 1 of this article, unless such processing is legally prohibited.

Article 6 – Security measures

  1. Data Processor implements all appropriate technical and organisational measures to prevent loss of personal data or any form of unlawful processing. These measures shall guarantee an adequate level of protection of the personal data being processed.
  2. Data Processor will at least take the following security measures:
    • Encryption of digital files containing personal data
    • Security of the network connection with Secure Socket Layer (SSL) technology or a similar technology
    • Restriction of access to the personal data to authorised employees
    • Back-ups of the personal data to restore them in time in case of physical or technical incidents
  3. Data Processor shall provide Data Controller with all available information to provide Data Controller assistance in carrying out security measures, conducting audits and inspections and carrying out data protection impact assessments.
  4. The Controller can contribute or request audits and inspections but may not conduct an audit more than once per calendar year. The audit shall be proceeded by an independent company, which is not a competitor of the Processor or related. The Controller shall reimburse the Processor for any cost or expenses incurred as a result of the audit.

Article 7 – Security incidents

  1. Data Processor will report any theft, loss, misuse or other form of data breach to Data Controller as soon as possible. This report includes, as far as possible, at least the following: the nature of the breach, the categories and scope of the personal data concerned, the likely consequences of the data breach, the measures Data Processor has taken and the contact details for Data Controller to obtain more information.
  2. If needed, Data Processor will fully cooperate to inform the authorities and Data Subjects about such security incidents or data breaches. In addition, Data Processor will fully cooperate in carrying out risk assessments, analysing the cause of the incident or breach, identifying required corrective measures and implementing those measures.

Article 8 – Duration and termination

  1. Parties enter into this Agreement for an indefinite period.
  2. This Agreement may be terminated by the end of each month, subject to a six months notice.
  3. If this Agreement is terminated or dissolved, Parties must continue to comply with the provisions of this Agreement regarding confidentiality, liability, indemnification and all other provisions that are intended by nature to remain applicable between the parties after terminations or dissolution of this Agreement.
  4. If this Agreement is terminated or dissolved, Data Processor will return all data, including personal data, which are processed by Data Processor based on this Agreement, to Data Controller at his request. Data Controller must submit this request to Data Processor within four weeks. After this period, Data Processor will safely remove or destroy all personal data, including any copies of it, unless Data Processor is legally obliged to store the (personal) data for a longer period.

Article 9 – Confidentiality and non-disclosure

  1. Data Processor will treat all personal data and other data received by Data Controller as confidential. Data Processor will limit the access to this data to persons working for Data Processor, who need access to correctly process the data on behalf of Data Controller.
  2. All (personal) data, Data Processor receives based on this Agreement are subject to a non-disclosure obligation towards third parties. All persons employed by or working for Data Processor, as well as Data Processor itself, are required to remain secrecy regarding the personal data.
  3. Data Processor will not provide third parties with the (personal)data or copy, multiply or otherwise make the personal data public, without permission of Data Controller.

Article 10 – Rights of Data Subjects

  1. Data Processor will assist Data Controller with all requests which may be received from Data Subjects, such as the right to access, rectification or erasure.
  2. If Data Processor receives a request from a third party to provide access to the personal data based on an alleged (legal) obligation, data Processor will inform Data Controller in writing before he provides the third party access, so Data Controller can assess whether the request is legitimate.

Article 11 – People working under the authority of Data Processor

The obligations for Data Processor arising from this Agreement also apply to those who process personal data under the authority of Data Processor, including but not limited to employees.

Article 12 – Sub Processors


Processor Location of Processing Purpose of Processing
OVH France & Germany Providing hosting services for the CookieFirst website and applications
Providing API for saving data.
Storage of CDN log data
BunnyWay Slovenia Provider of Content Delivery Network ensuring global performance of the cookie banner.
Zendesk United States Provider of support ticket system. NO consent data is sent to this service. We only share your email and name when you send a support request.
  1. Data Processor may appoint new Sub Processors for the processing of the personal data. Data Processor will notify Data Controller of the addition or replacement of any Sub Processors. Data Processor is then also offered the possibility to object to this. In addition, Data Controller may request an overview of all appointed Sub Processors.

Article 13 – Indemnification

  1. Data Processor is responsible for all all personal data (or other data) that Data Controller has shared with Data Processor. Data Processor indemnifies Data Controller against all claims by third parties or fines by the Autoriteit Persoonsgegevens because of the transfer of this Data.
  2. Data Processor is only liable for direct damage suffered by Data Controller, that is unequivocally caused by a shortcoming of Data Processor.
  3. The limitations of liability included in this article do not apply if the damage is caused as a consequence of the wilful intent or gross negligence of Processor.
  4. The Data Processor is not liable for damages or fines that incur from wrong use of the software the Data Processor provides to the Data Controller.

Article 14 – Nullity

If a part of this Agreement is deemed void or voidable, this does not change the validity of the rest of this Agreement. Any invalid provision shall be replaced by a provision that is valid and which interpretation shall be as close as possible to the intent of the invalid provision.

Article 15 – Final provision

  1. This Agreement can only be amended in writing.
  2. This Agreement replaces all prior agreements between parties.

Article 16 – Applicable law

Dutch law.

Article 17 – Competent court

The court in Amsterdam.