The situation
A medium-sized Dutch municipality (approximately 60,000 residents) works with over 120 external vendors that process personal data in some form:
- IT vendors: case management system, financial system, website, cloud services
- Social domain: youth care providers, social support providers, debt counselling
- Civil affairs: passport printers, civil registry system, cemetery administration
- Facilities: payroll, occupational health, security, cleaning
- Public space: waste collection, CCTV systems, parking enforcement
The challenges
Lack of overview
DPAs are scattered across inboxes, shared drives and the contract management system. Nobody has a complete overview.
Outdated agreements
Many DPAs were drafted when the GDPR took effect in 2018 and have not been reviewed since.
Special category data
Municipalities process special category data in the social domain (health, youth care) and civil affairs (biometrics), raising the bar for DPAs.
Staff turnover
The privacy officer changes, department heads retire, contract managers move on. Knowledge of existing arrangements is lost.
The approach
Step 1: Inventory
The municipality inventories all external parties processing personal data, documenting data types, data subjects, legal bases and DPA status.
Step 2: Central management
All DPAs are centralised in a tool like DPAkit. Expiry dates, contacts, sub-processor lists and security certificates are recorded per vendor.
Step 3: Review and renewal
Outdated DPAs are reviewed and renewed with Art. 28-compliant agreements sent for signature via the platform.
Step 4: Ongoing management
Automatic renewal reminders. Sub-processor changes are monitored. Security certificates are stored with expiry alerts.
The result
- Complete overview of all 120+ vendors and their DPAs
- No more outdated or missing agreements
- Audit-ready: the municipality can present a complete overview in minutes
- Less dependency on individual staff members
- Better control over sub-processors and data transfers
Lessons learned
- Start with vendors processing the most sensitive data
- Involve all departments in the inventory
- Plan realistic timelines: reviewing 120 vendors takes months, not weeks
- Assign clear responsibility for maintaining the register
- Invest in a tool that maintains overview even when staff changes