Data Processing Addendum
Version v1 · en
Data Processing Addendum
Version: 2026-05-20 — English courtesy translation. The Dutch version is authoritative.
NOT LEGALLY VALID — REASONABLE DRAFT ONLY. This document is shipped as a starting point and must be reviewed and adapted by a qualified legal professional before production use. Do not rely on it as legal advice.
This Data Processing Addendum (the "DPA") forms an integral part of any Agreement between Risk at Work B.V. ("Risk at Work B.V.") and the Client under which Risk at Work B.V. processes Personal Data on behalf of the Client.
In the event of conflict between this DPA and the other documents forming the Agreement, this DPA prevails with respect to the processing of Personal Data.
Article 1 — Definitions
1.1 Terms used in this DPA that are also defined in the General Terms and Conditions have the meaning given there. In addition, the following terms apply:
Applicable Data Protection Law: Regulation (EU) 2016/679 (the "GDPR"), the Dutch GDPR Implementation Act (Uitvoeringswet Algemene verordening gegevensbescherming, "UAVG"), and any other data protection or privacy law applicable to the processing of Personal Data under the Agreement, as amended from time to time.
Data Subject, Controller, Processor, Personal Data Breach, Processing (and to Process), Special Categories of Personal Data, and Supervisory Authority: have the meanings given in the GDPR.
Sub-processor: any third party engaged by Risk at Work B.V. (or by any of its affiliates) to Process Personal Data on behalf of the Client in connection with the Agreement.
Standard Contractual Clauses or "SCCs": the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission pursuant to Decision 2021/914, as amended from time to time.
Technical and Organisational Measures or "TOMs": the technical and organisational measures implemented by Risk at Work B.V. to protect Personal Data, as described in Annex II and on our trust centre page at /trust.
Trust Centre: the online resource at /trust providing current information on security certifications, sub-processors, and TOMs.
Article 2 — Scope and Roles
2.1 This DPA applies to the Processing of Personal Data carried out by Risk at Work B.V. as Processor on behalf of the Client as Controller, in the course of providing services under the Agreement.
2.2 The details of the Processing, including its subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects, are set out in Annex I.
2.3 Where Risk at Work B.V. Processes Personal Data for its own purposes — including for account and relationship management, billing, credit assessment, compliance with its own legal obligations (including Know-Your-Customer and anti-money laundering obligations), and improvement of its services by means of aggregated and anonymised analytics — Risk at Work B.V. acts as an independent Controller. Such Processing is not governed by this DPA but by Risk at Work B.V.'s privacy statement.
2.4 This DPA applies for as long as Risk at Work B.V. Processes Personal Data on behalf of the Client, and with respect to any obligations that by their nature survive, also thereafter.
Article 3 — Obligations of the Client
3.1 The Client warrants that it has a valid legal basis under Applicable Data Protection Law for each Processing activity it instructs Risk at Work B.V. to perform, and has complied with all information obligations towards Data Subjects required by Applicable Data Protection Law.
3.2 The Client is responsible for the accuracy, quality, lawfulness, and relevance of the Personal Data it provides to Risk at Work B.V., and for the means by which it obtained such Personal Data.
3.3 The Client shall not provide Risk at Work B.V. with Personal Data that is not required for the performance of the services under the Agreement. In particular, the Client shall not provide Special Categories of Personal Data or Personal Data relating to criminal convictions and offences unless this is expressly agreed in the Order Form or Annex I and appropriate safeguards have been documented.
3.4 The Client shall give Risk at Work B.V. timely written notice of any material change to the Processing that affects Risk at Work B.V.'s obligations under this DPA or Applicable Data Protection Law, including changes to the purposes, categories of Personal Data, or categories of Data Subjects.
Article 4 — Obligations of Risk at Work B.V.
4.1 Processing on Instructions
4.1.1 Risk at Work B.V. shall Process Personal Data only on documented instructions from the Client, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by Union or Member State law to which Risk at Work B.V. is subject. In such a case, Risk at Work B.V. shall inform the Client of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
4.1.2 The Client's instructions are set out in the Agreement, the Order Form, this DPA (including Annex I), and any further written instructions given by the Client in the course of the Agreement that are consistent therewith.
4.1.3 Risk at Work B.V. shall promptly inform the Client if, in its opinion, an instruction from the Client infringes Applicable Data Protection Law. Risk at Work B.V. may suspend performance of an instruction it reasonably considers unlawful until the Client confirms or modifies the instruction.
4.2 Confidentiality
4.2.1 Risk at Work B.V. shall ensure that persons authorised to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to Personal Data is restricted to personnel who require such access to perform the services under the Agreement.
4.3 Security
4.3.1 Risk at Work B.V. shall implement appropriate Technical and Organisational Measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of Processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons.
4.3.2 The TOMs implemented by Risk at Work B.V. are described in Annex II and on the Trust Centre. Risk at Work B.V. may update the TOMs from time to time, provided that the level of protection is not materially reduced.
4.3.3 Risk at Work B.V. shall test, assess, and evaluate the effectiveness of the TOMs on an ongoing basis and shall make continuous improvements where appropriate.
4.4 Sub-processors
4.4.1 The Client grants Risk at Work B.V. general authorisation to engage Sub-processors, subject to the conditions in this Article.
4.4.2 Risk at Work B.V.'s current list of Sub-processors is published on the Trust Centre. The Client may subscribe to notifications of changes to this list.
4.4.3 Risk at Work B.V. shall notify the Client at least thirty (30) days before engaging a new Sub-processor or replacing an existing Sub-processor. The Client may object to the change in writing within that thirty-day period on reasonable grounds relating to Applicable Data Protection Law. The Parties shall discuss the objection in good faith and seek a resolution. If the Parties cannot agree within a further thirty (30) days, either Party may terminate the affected Services under the Agreement without liability, in which case Risk at Work B.V. shall refund any fees prepaid for services not yet rendered.
4.4.4 Risk at Work B.V. shall impose on each Sub-processor, by written contract, data protection obligations no less protective than those set out in this DPA, in particular providing sufficient guarantees to implement appropriate TOMs such that the Processing meets the requirements of Applicable Data Protection Law.
4.4.5 Risk at Work B.V. remains fully liable to the Client for the performance of each Sub-processor's obligations.
4.5 Data Subject Rights
4.5.1 Risk at Work B.V. shall, taking into account the nature of the Processing, assist the Client by appropriate technical and organisational measures — insofar as this is possible — in fulfilling the Client's obligation to respond to requests by Data Subjects to exercise their rights under Chapter III of the GDPR (access, rectification, erasure, restriction of Processing, data portability, objection, and not being subject to automated decision-making).
4.5.2 If Risk at Work B.V. receives a request from a Data Subject directly, it shall not respond to the request itself (other than to direct the Data Subject to the Client) and shall forward the request to the Client without undue delay.
4.6 Assistance with Controller Obligations
4.6.1 Risk at Work B.V. shall assist the Client in ensuring compliance with the Client's obligations under Articles 32 to 36 of the GDPR, taking into account the nature of the Processing and the information available to Risk at Work B.V.. This includes assistance with security of Processing, notification of Personal Data Breaches, Data Protection Impact Assessments, and prior consultation with Supervisory Authorities.
4.6.2 Assistance beyond the routine provision of information and standard functionality may be charged at Risk at Work B.V.'s standard rates.
4.7 Personal Data Breaches
4.7.1 Risk at Work B.V. shall notify the Client of a Personal Data Breach affecting the Client's Personal Data without undue delay after becoming aware of it, and in any event within forty-eight (48) hours.
4.7.2 The notification shall include, to the extent known at the time: (a) a description of the nature of the Personal Data Breach, including where possible the categories and approximate number of Data Subjects and Personal Data records concerned; (b) the name and contact details of Risk at Work B.V.'s data protection contact; (c) a description of the likely consequences of the Personal Data Breach; and (d) a description of the measures taken or proposed to address the Personal Data Breach and mitigate its adverse effects. Where not all information is available at the time of initial notification, Risk at Work B.V. shall provide the remaining information in phases as it becomes available.
4.7.3 Risk at Work B.V. shall cooperate with the Client and provide reasonable assistance in the Client's response to the Personal Data Breach, including with respect to notifications to the Supervisory Authority and to Data Subjects where required.
4.7.4 Risk at Work B.V. shall investigate Personal Data Breaches, take reasonable measures to mitigate their effects, and take reasonable steps to prevent recurrence. The Parties shall coordinate in good faith on the content of any public statements concerning the Personal Data Breach.
4.8 Records
4.8.1 Risk at Work B.V. shall maintain records of Processing activities carried out on behalf of the Client as required by Article 30(2) of the GDPR, and shall make them available to the Client or the Supervisory Authority on request.
4.9 Deletion or Return
4.9.1 On termination of the Agreement, Risk at Work B.V. shall, at the Client's choice, delete or return all Personal Data Processed on behalf of the Client, and delete existing copies, unless Union or Member State law requires storage of the Personal Data.
4.9.2 The Client may request return or deletion in writing within thirty (30) days of termination, specifying the preferred format for any return. In the absence of such a request, Risk at Work B.V. shall delete the Personal Data within ninety (90) days of termination, save to the extent retention is required by law.
4.9.3 On written request, Risk at Work B.V. shall confirm in writing that deletion has been completed. Risk at Work B.V. is not required to provide forensic proof of deletion.
4.9.4 Personal Data contained in back-up systems shall be deleted or overwritten in the ordinary course of Risk at Work B.V.'s back-up retention cycle and shall remain subject to the security and confidentiality obligations of this DPA until deletion.
Article 5 — Cross-Border Transfers
5.1 Risk at Work B.V. shall not transfer Personal Data to a country outside the European Economic Area (the "EEA") or to an international organisation unless a lawful transfer mechanism under Applicable Data Protection Law is in place.
5.2 Where Risk at Work B.V. engages a Sub-processor located outside the EEA in a country not benefiting from an adequacy decision of the European Commission, the transfer shall be governed by the Standard Contractual Clauses, Module 3 (Processor to Sub-processor) or Module 2 (Controller to Processor), as applicable, which are incorporated into this DPA by reference. Where the SCCs require specifications (docking clause, optional clauses, governing law, supervisory authority), the specifications set out in Annex III apply.
5.3 The Parties agree to implement appropriate supplementary measures where these are required in light of a transfer impact assessment, as described in Annex III.
5.4 Where the Client is established outside the EEA and transfers Personal Data to Risk at Work B.V. in the EEA, any transfer of Personal Data by Risk at Work B.V. back to the Client or to a Sub-processor in the Client's jurisdiction or a third country shall similarly be subject to an appropriate transfer mechanism.
Article 6 — Audit
6.1 Risk at Work B.V. shall make available to the Client all information necessary to demonstrate compliance with the obligations laid down in this DPA and Article 28 of the GDPR.
6.2 Risk at Work B.V. maintains third-party certifications and audit reports relevant to its Processing activities, which are listed on the Trust Centre. On the Client's written request, and subject to confidentiality, Risk at Work B.V. shall make available the most recent version of such certifications or reports. The Client agrees that such information shall serve to fulfil its audit rights under Applicable Data Protection Law.
6.3 If the information provided under Article 6.2 is not sufficient to demonstrate compliance, the Client may, on reasonable prior written notice of at least thirty (30) days, conduct an audit of Risk at Work B.V.'s Processing activities on behalf of the Client. The audit may be conducted by the Client or by an independent, qualified third-party auditor appointed by the Client who is not a competitor of Risk at Work B.V. and who has signed an appropriate confidentiality agreement with Risk at Work B.V..
6.4 Audits shall be conducted no more than once in any twelve-month period (save where a further audit is required by a Supervisory Authority or follows a material Personal Data Breach), during normal business hours, in a manner that does not unreasonably interfere with Risk at Work B.V.'s operations, and shall be subject to appropriate confidentiality undertakings.
6.5 The Client shall bear its own costs of the audit and shall reimburse Risk at Work B.V. for the time and costs it incurs in cooperating with the audit, charged at Risk at Work B.V.'s standard rates. Where the audit reveals material non-compliance by Risk at Work B.V., Risk at Work B.V. shall bear its own costs.
6.6 Risk at Work B.V. shall promptly remediate any material non-compliance identified by an audit.
Article 7 — Liability
7.1 Each Party is liable to the other Party and to Data Subjects for the damages caused by its non-compliance with Applicable Data Protection Law, to the extent provided under such law.
7.2 The limitations of liability set out in the General Terms and Conditions apply to this DPA, except to the extent that Applicable Data Protection Law prohibits such limitations.
Article 8 — General Provisions
8.1 Amendments. Risk at Work B.V. may amend this DPA from time to time to reflect changes in Applicable Data Protection Law or in Risk at Work B.V.'s Processing practices. Material amendments shall be notified to the Client at least thirty (30) days before they take effect. The Client may object to a material amendment in writing within that thirty-day period on reasonable grounds relating to Applicable Data Protection Law, in which case the Parties shall discuss the objection in good faith.
8.2 Conflicts. In the event of conflict between this DPA and the General Terms and Conditions or any Order Form, this DPA prevails with respect to the Processing of Personal Data. The SCCs, where incorporated, prevail over this DPA to the extent of any conflict concerning cross-border transfers.
8.3 Severability. If any provision of this DPA is or becomes invalid or unenforceable, the remaining provisions shall remain in full force. The invalid provision shall be replaced by a valid provision approximating its original intent.
8.4 Governing law and jurisdiction. This DPA is governed by Dutch law. Disputes arising out of this DPA are subject to the dispute resolution provisions of the General Terms and Conditions.
8.5 Language. This DPA is published in Dutch and is available in an English courtesy translation. In the event of any inconsistency between the language versions, the Dutch version prevails. Where the SCCs are incorporated, the authoritative language of the SCCs is English, as adopted by the European Commission.
Annex I — Description of the Processing
A. Subject Matter and Nature of the Processing
Risk at Work B.V. Processes Personal Data to provide the services agreed in the Order Form, which may include: consultancy services (analysis, advisory, model development, implementation support); software-as-a-service (hosting, operation, support, maintenance); and AI services (training, inference, deployment support).
The specific subject matter and nature of the Processing for a given engagement are determined by the Order Form and the Client's instructions.
B. Purpose of the Processing
Provision of the services agreed in the Order Form, in accordance with the Client's documented instructions.
C. Duration of the Processing
For the duration of the Agreement and thereafter as required by Article 4.9 of this DPA.
D. Categories of Personal Data
The categories of Personal Data Processed depend on the services provided and are determined by the Client. Unless otherwise specified in the Order Form, Personal Data may include:
- Identification and contact data such as name, email address, telephone number, postal address, employee or customer reference numbers
- Professional data such as job title, employer, department, work history
- Financial data such as transaction history, account balances, payment data, creditworthiness indicators, actuarial reserves data
- Technical and usage data such as IP address, device identifiers, usage logs, interaction history with software
- Content of communications such as messages, documents, queries submitted to AI services
- Any additional categories specified in the Order Form or Client's instructions
The Client shall not provide Special Categories of Personal Data or Personal Data relating to criminal convictions and offences unless expressly agreed and appropriate safeguards are documented in the Order Form.
E. Categories of Data Subjects
The categories of Data Subjects depend on the services provided and are determined by the Client. Categories may include:
- The Client's employees, contractors, and other personnel
- The Client's customers and prospective customers
- End users of the Client's products or services
- Counterparties of the Client (including in financial transactions)
- Other natural persons whose data the Client processes and provides to Risk at Work B.V. for the purposes of the services
F. Special Categories and Children's Data
Not applicable unless expressly specified in the Order Form. Where the Processing involves Special Categories of Personal Data, Personal Data relating to criminal convictions and offences, or data of children under the age of sixteen, the Order Form shall specify the additional safeguards.
Annex II — Technical and Organisational Measures
Risk at Work B.V. implements the TOMs described below. Current detailed information is maintained on the Trust Centre at /trust and updated as measures evolve.
A. Access Control
- Role-based access control with least-privilege principles for all systems Processing Personal Data
- Multi-factor authentication for administrative access and remote access
- Individual user accounts with unique credentials; no shared accounts
- Periodic review of access rights and prompt revocation on role change or departure
B. Encryption
- Encryption in transit using TLS 1.2 or higher for all Personal Data transferred over public networks
- Encryption at rest using industry-standard algorithms (AES-256 or equivalent) for Personal Data stored in production systems
- Secure key management using dedicated key management services
C. Integrity and Availability
- Regular automated backups with encryption at rest
- Documented disaster recovery and business continuity procedures
- Redundancy and resilience measures for critical infrastructure
- Logging and monitoring of access to and operations on Personal Data
D. Organisational Measures
- Confidentiality obligations for all personnel with access to Personal Data, binding through employment contracts
- Mandatory data protection and security training on onboarding and periodically thereafter
- Information security policy and procedures reviewed at least annually
- Documented incident response procedure, including Personal Data Breach notification
- Data protection contact point responsible for overseeing compliance
E. Vendor Management
- Due diligence on Sub-processors before engagement
- Written agreements imposing data protection obligations no less protective than this DPA
- Periodic review of Sub-processor compliance
F. Physical Security
- Personal Data is Processed in data centres operated by reputable cloud providers meeting recognised security standards (ISO 27001, SOC 2, or equivalent)
- Risk at Work B.V.'s own premises are access-controlled; no production Personal Data is stored on local devices
G. Data Minimisation and Retention
- Personal Data is Processed only to the extent necessary for the services
- Retention periods are aligned with the Agreement and the Client's instructions
- Pseudonymisation and anonymisation are used where appropriate
H. Ongoing Improvement
- The TOMs are reviewed periodically and updated to reflect changes in the state of the art, emerging threats, and the nature of the Processing
- Specific certifications and attestations are listed on the Trust Centre
Annex III — Cross-Border Transfer Specifications
A. Standard Contractual Clauses — Module Selection
Where Risk at Work B.V. transfers Personal Data to a Sub-processor outside the EEA in a country not benefiting from an adequacy decision, Module 3 (Processor to Sub-processor) of the SCCs applies, with Risk at Work B.V. as data exporter and the Sub-processor as data importer.
Where the Client is established outside the EEA and Risk at Work B.V. acts as Processor in the EEA receiving Personal Data from the Client, Module 2 (Controller to Processor) applies, with the Client as data exporter and Risk at Work B.V. as data importer.
B. Optional Clauses and Specifications
- Clause 7 (Docking clause): Applies.
- Clause 9(a) (Sub-processors): Option 2 (general written authorisation) applies; the time period for notification of intended changes is thirty (30) days, as specified in Article 4.4.3 of this DPA.
- Clause 11(a) (Redress): The option to include an independent dispute resolution body does not apply.
- Clause 17 (Governing law): The law of the Netherlands applies.
- Clause 18 (Forum and jurisdiction): The competent court in Amsterdam, the Netherlands, has jurisdiction, without prejudice to Data Subjects' rights under Clause 18(c).
C. Supervisory Authority
The competent Supervisory Authority for the Client, unless otherwise specified in the Order Form, is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
D. Annexes to the SCCs
- Annex I.A (Parties): The Client as data exporter (or data importer, as applicable); Risk at Work B.V. as data importer (or data exporter, as applicable); the relevant Sub-processor as applicable. Contact details are those specified in the Order Form.
- Annex I.B (Description of the transfer): As described in Annex I of this DPA.
- Annex I.C (Competent supervisory authority): As specified in Section C above.
- Annex II (Technical and organisational measures): As described in Annex II of this DPA.
- Annex III (List of sub-processors): As published on the Trust Centre.
E. Transfer Impact Assessment and Supplementary Measures
Risk at Work B.V. has conducted a transfer impact assessment for the jurisdictions to which it transfers Personal Data, taking into account the factors identified in EDPB Recommendations 01/2020. Where the assessment indicates that the laws and practices of the destination country may impinge on the effectiveness of the SCCs, Risk at Work B.V. implements supplementary measures, which may include:
- Enhanced encryption with key management by the data exporter
- Pseudonymisation of Personal Data before transfer
- Contractual commitments by the data importer regarding government access requests
- Policies on challenging disproportionate government access requests where lawfully possible
Current information on supplementary measures applicable to specific transfers is available on the Trust Centre.
This DPA is available at /legal/dpa/v1 and may be updated in accordance with Article 8.1.