JavaScript is required

Data Processing Agreement

Client as mentioned in the main agreement of which this data processing agreement forms a part.

and

The MedGuide Company B.V., trading under the name The MedGuide Company, registered in the Commercial Register of the Chamber of Commerce under number 76091465, having its registered office and place of business in (1013 AP) Amsterdam at Danzigerkade 227 B (hereinafter referred to as MedGuide or Processor), herein legally represented by its general director, Mr. J.T. van der Kleij;

hereinafter collectively referred to as: Parties.

The Parties take the following into consideration:
  • As the Controller for the personal data under the General Data Protection Regulation (hereinafter referred to as: GDPR), the Client is obliged to enter into a data processing agreement with the Processor;
  • In the context of the work agreed between the parties, which is laid down in an agreement and which will be executed by the Processor, the Processor will process personal data belonging to the Client, on behalf of and as instructed by the Client, without being subject to the direct authority of the Client;
  • During the execution of the work, the Processor will process personal data in accordance with the instructions and under the responsibility of the Client;
  • The Client and the Processor have taken note of Article 32 of the GDPR in order to choose an appropriate level of protection;
  • Additionally, other processing operations may be assigned in writing by the Client to the Processor, which will be attached as an annex to this data processing agreement;
  • The Processor will only carry out data processing that has been instructed in writing by the Client;
  • If, on the instructions of the Client, more or other personal data are processed, or if processing is carried out differently than described in the applicable annex, this data processing agreement shall also apply to those processing operations and personal data.

And agree as follows:
Article 1. Definitions
Unless defined otherwise in this Agreement, the terms used have the meaning assigned to them in the General Data Protection Regulation (EU) 2016/679 (GDPR).
Article 2. Processing of personal data
  1. Client grants mandate to Processor, which is accepted by Processor, to process personal data in accordance with this data processing agreement.
  2. Client remains the Controller for the data processing. Processor has no independent control over the personal data processed for Client in accordance with this data processing agreement.
  3. Processor processes the personal data exclusively based on written instructions from Client, including with regard to the transfer of personal data to a third country or international organization, unless applicable law requires Processor to process. In such a case, Processor shall notify Client of that legal requirement prior to the processing, unless that law prohibits such notification on important grounds of public interest. Processor shall immediately notify Client if an instruction infringes the GDPR or other data protection provisions.
  4. To the extent that Processor processes pseudonymized or anonymized data for the purpose of onward transfer to third parties for Processor's own commercial or research purposes, Processor qualifies for that specific processing as an independent controller within the meaning of Article 4, point 7, GDPR. This processing falls outside the scope of the Controller's power to issue instructions as referred to in this Article and is regulated separately in Annex 3 (Arrangement on onward transfer to third parties).
  5. Client is responsible for ensuring that a valid legal basis exists for the processing of the personal data in accordance with privacy legislation.
  6. Processor shall process the personal data mentioned in the applicable Annex 1 and strictly necessarily provided by Client exclusively for the activities described therein. Processor shall refrain from performing other actions, unless otherwise agreed in the applicable annex.
Article 3. Onward transfer to third parties
  1. Processor is entitled to provide pseudonymized or anonymized data, derived from the personal data processed in the context of this agreement, to third parties (including pharmaceutical companies, scientific institutions, and government bodies), exclusively if:
    1. Processor has established a documentable lawful basis for this processing, which basis is independent of the basis used by the Controller for the primary services.
    2. Controller has previously informed the data subjects (patients) in accordance with Articles 13 and 14 of the GDPR and, where legally required, has obtained explicit consent in accordance with Article 9, paragraph 2 under a, of the GDPR.
    3. The applied anonymization or pseudonymization methodology is documented and will be provided upon request of the Controller or a supervisory authority.
    4. Processor has conducted a Data Protection Impact Assessment in accordance with Article 35 of the GDPR prior to the commencement of the processing.
  2. Controller undertakes to offer patients the possibility to object to the onward transfer of their data for the purposes referred to in this Article, without this affecting access to regular pharmaceutical services.
  3. Processor is an independent controller for the processing referred to in this Article and accepts the resulting liability towards data subjects and supervisory authorities.
Article 4. Compliance with laws and regulations
  1. In processing personal data as described in Article 2 and the applicable annex, the Processor shall act in accordance with the GDPR and other applicable laws and regulations regarding data protection.
Article 5. Liability
  1. Processor is liable for direct damages resulting from an attributable failure to comply with this data processing agreement, as well as in connection with an attributable violation of the GDPR and all other applicable European privacy regulations and self-regulation. Direct damage is exclusively understood to mean: the reasonable costs incurred to make the deficient performance of Processor comply with the data processing agreement, to the extent that this can be attributed to Processor.
  2. Processor is never liable for indirect damage, consequential damage, damage to reputation, lost profit, lost turnover or savings, and/or reduced goodwill.
  3. The total liability of Processor on any ground whatsoever is limited to the amount actually paid out in the applicable case by Processor's liability insurer.
  4. If Processor's insurer does not pay out compensation and Processor is nevertheless obliged to compensate the damage on the basis of a judgment, then the scope of Processor's liability is limited to the total invoice amounts paid by Client to Processor over a period of a maximum of 12 months preceding the event.
  5. The provisions of this Article also apply with respect to the (legal) persons engaged by Processor for the execution of the services.
  6. The limitations and exclusions stated in this Article shall lapse in the event of intent or willful recklessness by the management of Processor.
Article 6. Security measures and inspection
  1. Processor will take, maintain, evaluate and, if necessary, adjust and update appropriate technical and organizational measures to protect personal data against loss, theft or against any form of unlawful processing. These measures guarantee, taking into account the nature, scope, context and purpose of the processing, the state of the art and the costs of implementation, an appropriate level of security given the probability and severity of various risks involved in processing personal data to be protected, and comply with the provisions of Article 32 GDPR.
  2. At the request of Client, Processor shall make available all information necessary to demonstrate compliance with the provisions of paragraph 1.
  3. Processor only processes or has personal data processed within the European Economic Area (EEA). However, if Processor wishes to process or have processed the personal data of Client outside the European Economic Area, it will do so or have it done with the prior written consent of Client and exclusively in countries that have been designated by the European Commission as countries with an adequate level of protection or that offer an adequate level of protection through additional measures.
  4. Processor enables Client to conduct or have conducted an audit once a year, with the aim of verifying compliance with what is stipulated in this data processing agreement. Processor will cooperate with this and make all information relevant to the audit available in a timely manner, which is necessary to demonstrate compliance with the obligations laid down in the data processing agreement.
  5. Client will not perform an audit at Sub-processors, because Processor itself is responsible for this.
  6. The persons performing an audit will conform to the security procedures in force at Processor. The costs for an audit are fully borne by Client, unless the audit shows that Processor has acted attributably in breach of this data processing agreement on non-minor points.
  7. Client will limit the audit to what is established in this data processing agreement and to the data processing operations and personal data of Client. Data processing operations that Processor executes for other Clients are excluded from this audit. Client shall keep confidential all information it becomes aware of during the audit. This also applies to the third party engaged by Client who performs the audit. Client ensures that the normal work processes of Processor are not disrupted during an audit and will inform Processor well in advance about an audit to be scheduled.
Article 7. Notification obligation for personal data breaches
  1. If Processor, in processing personal data, becomes aware of a personal data breach (data breach), Processor shall notify Client thereof at the latest within 48 hours after discovery. In the meantime, Processor shall take all possible technical and organizational measures to stop, prevent, and/or remedy the data breach. When notifying, Processor shall provide information (insofar as known) regarding the nature of the breach, the nature of the leaked personal data, the technical protection measures, and other relevant facts and circumstances that are important to determine whether the supervisory authority and/or the data subject must be informed by Client.
  2. Processor will fully complete Annex 2 'Notification of personal data breach by Processor' and send it digitally to Client. Client is responsible for immediately notifying Processor if any change to this information occurs. Processor assumes the accuracy of the information provided by Client.
  3. Processor documents all data breaches and security incidents. The documentation shall be provided upon written request of Client, in order to ensure that Client is able to submit it to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
  4. If there is an obligation to make a notification to the supervisory authority or to inform the data subjects, this shall be done exclusively by Client. Processor shall cooperate in this regard.
  5. Taking into account the nature of the processing and the information available to it, Processor shall assist Client in complying with the obligations under Article 35 GDPR (data protection impact assessment) and Article 36 GDPR (prior consultation).
Article 8. Engagement of Sub-processors
  1. Processor is not permitted to use a Sub-processor in the context of this data processing agreement, unless Client has given its prior written consent.
  2. If Processor wishes to process the personal data outside the European Economic Area, this may only take place in countries that have been designated by the European Commission as countries with an adequate level of protection or that offer an adequate level of protection through additional measures.
  3. Client grants permission to Processor for the engagement of the Sub-processors listed in the applicable annex.
  4. The Sub-processor provides sufficient guarantees regarding the application of appropriate technical and organizational measures so that the processing meets the requirements of this data processing agreement and the GDPR.
  5. If Processor has engaged a Sub-processor, Processor remains fully liable for the compliance with all obligations by this Sub-processor. In a written agreement, Processor shall impose the same obligations on the Sub-processor as those arising for Processor from this data processing agreement, so that the Sub-processor is also bound by these provisions.
  6. Processor must maintain a list of Sub-processors, including the tasks to be performed.
  7. Pharmaceutical companies, scientific institutions, and government bodies receiving data in the context of Article 3 of this agreement do not qualify as sub-processors within the meaning of this Article, as they do not act on behalf of or under the instruction of Processor, but process for their own purposes. Only Article 3 applies to this onward transfer.
Article 9. Duty of confidentiality
  1. Processor, its staff, and third parties engaged by it are obliged to maintain the confidentiality of the personal data of which they become aware.
  2. Processor shall only grant access to the personal data to its employees and third parties engaged by it to the extent necessary for performing the data processing instructed by Client.
  3. Processor shall demonstrably oblige the persons in its employ or performing work on its behalf to maintain confidentiality, including a sanction policy, with regard to the personal data of which they may become aware.
  4. The Processor's duty of confidentiality can only be breached if a legal provision obliges the disclosure of personal data or if the officer designated for this purpose by Client has indicated the necessity of disclosure to Processor.
  5. If a supervisory authority of Client requests inspection of the data processing, Processor shall provide all necessary cooperation so that Client can comply with its obligations.
  6. The duty of confidentiality applies both during and after the completion of the work and continues to exist even after the termination of this data processing agreement.
  7. Processor shall inform Client of any request for access, disclosure, or other form of retrieval and communication of the personal data, unless legislation prohibits this notification for important reasons of public interest.
Article 10. Rights of data subjects
  1. If a data subject invokes one of their rights based on Articles 15 to 22 of the GDPR with the Processor, the Processor shall forward this request to the Client as soon as possible.
  2. Processor will provide full and timely assistance to Client in fulfilling its obligation to respond to requests from data subjects. The costs associated with this shall be borne by Client.
Article 11. Final provisions
  1. No general terms and conditions apply to this data processing agreement. Dutch law is applicable. The applicability of the Vienna Convention on Contracts for the International Sale of Goods (CISG) is excluded. Disputes will be submitted to the District Court of the district where Processor has its registered office.
  2. If provisions are included in another agreement or document between Client and Processor that deviate from what is stipulated in this data processing agreement, the provisions of this data processing agreement shall prevail.
  3. Amendments to this data processing agreement are only valid if they have been agreed upon in writing between the Parties. The Parties are not entitled to transfer this data processing agreement to a third party.
  4. This data processing agreement enters into force at the moment it is signed by the Parties and has a duration equal to that of the main agreement. This data processing agreement cannot be terminated separately in the interim.
  5. Articles of the data processing agreement which by their nature are intended to remain applicable after the end of the data processing agreement, including but not limited to the article regarding liability, shall remain in full force and effect.

Appendix 1 - Description of Processing Activities

Activities
The following activities will be performed by the Processor:
  • Analyzing, prioritizing, and reporting pharmacotherapeutic problems for patients of the Client by means of a pharmacotherapeutic analysis.
  • Presenting results to the Client in an online results dashboard.
  • Making the research results available for export from the online results dashboard by the Client.
  • Generating pseudonymized or anonymized insight data for the purpose of onward transfer to third parties for pharmaceutical research, scientific research, or policy purposes of government bodies.
Data subjects
Patients of the Client.
Personal data
Processor receives the following personal data for this purpose:
  • Patient number
  • Name
  • Address
  • City
  • Email address
  • Phone number
  • Gender
  • Age or date of birth
  • Additional personal data necessary for the execution of the services

Client ensures that in the context of the agreed processing of personal data, no more personal data are provided than is strictly necessary for the performance of the agreement.
Retention periods
Data files
To avoid storing customer data unnecessarily on the servers of the MedGuide Platform, data files—if they are provided automatically—are deleted after 30 days.

Sub-processors within the European Economic Area
Client grants permission for the engagement of the following Sub-processors established within the European Economic Area:
NameAddress detailsProcessing activities
Microsoft NetherlandsEvert van Beekstraat 354, 1118 CZ SchipholMS Azure

Sub-processors outside the European Economic Area
Client grants permission for the engagement of the following Sub-processors established outside the European Economic Area:
  • Not applicable.

Appendix 2 - Personal Data Breach Notification by the Processor

Data breach notification
The Processor shall notify the Controller of a personal data breach within 48 hours after discovery. Updates will be provided as soon as available.

Breach notification form

1. Contact Persons

Processor contact person

Name
Jan van der Kleij
Function
Security Officer
Phone number
+31 (0)6-53838654
Email address
security@themedguidecompany.com

2. Is this a follow-up to a previous notification?

3. If 'yes' was answered to the previous question: what is the date of the original notification?

4. If 'yes' was answered to question 2: what is the purpose of the follow-up notification?

Check the correct option.

5. When choosing option B for question 4: what is the reason for the withdrawal?

6. Provide a summary of the incident in which the personal data breach occurred.

7. How many individuals' personal data are involved in the breach?

8. Describe the group of people whose personal data are involved in the breach.

9. When did the breach occur?

Choose the correct option and enter the date(s).

10. When was the breach discovered?

11. What is the nature of the breach?

Check the correct option(s). Note: multiple answers possible.

12. Which types of personal data are involved?

Check the correct option(s). Note: multiple answers possible.

13. What consequences can the breach have for the privacy of the data subject?

Check the correct option(s). Note: multiple answers possible.

14. What technical and organizational measures has your organization taken to address the breach and to prevent further breaches?

15. When was the data breach reported to the Client?

16. What means was used to make the report?

Check the correct option.

17. Have the personal data been encrypted, hashed, or otherwise made unintelligible or inaccessible to unauthorized parties?

Check the correct option.

18. If the personal data have been wholly or partially made unintelligible or inaccessible, in what way was this done?

19. In your opinion, is this report complete?

Check the correct option.

20. Conclusion

21. The form was received by the Client on

Annex 3 - Arrangement on onward transfer to third parties

This annex provides further elaboration on the onward transfer of pseudonymized or anonymized data by the Processor to third parties, as referred to in Article 2, paragraph 4 and Article 3 (Onward transfer to third parties) of the Data Processing Agreement. This annex thus forms the implementation framework within which the onward transfer actually takes place and with which MedGuide can demonstrate the required diligence and accountability (accountability, Art. 5, paragraph 2 GDPR).
1. Categories of authorized recipients and applicable lawful basis
MedGuide transfers pseudonymized or anonymized insight data onward exclusively to the categories of recipients mentioned below, and solely on the basis of the lawful basis specified therewith. Prior to any onward transfer to a (new) recipient, MedGuide shall establish in writing that the applicable basis has been met and shall record this in the documentation file referred to in Article 3.1 sub A and C of the Data Processing Agreement.
Recipient categoryPurpose of onward transferApplicable lawful basis
Pharmaceutical companiesPharmaceutical research, including efficacy and safety research and drug monitoring (pharmacovigilance)Legitimate interest (Art. 6, paragraph 1 sub f GDPR), in combination with the research exception of Art. 9, paragraph 2 sub j GDPR in conjunction with Art. 24 UAVG to the extent that the data is pseudonymized; if the data is fully anonymized, the GDPR does not apply
Scientific institutions (universities, research institutes)Scientific research into polypharmacy, medication safety, and efficacy of pharmaceutical careArt. 9, paragraph 2 sub j GDPR in conjunction with Art. 24 UAVG, taking into account the safeguards of Art. 89 GDPR (data minimization and pseudonymization)
Government bodies (e.g., IGJ, RIVM, Ministry of VWS)Policy purposes and public health monitoringLegal obligation (Art. 6, paragraph 1 sub c GDPR) where a concrete disclosure obligation exists, or the performance of a task carried out in the public interest (Art. 6, paragraph 1 sub e GDPR); in the absence of this, recourse is made to (further) anonymization

This list is exhaustive: onward transfer to categories of recipients other than those mentioned above is not permitted without prior written amendment to this annex.
2. Mandatory contractual provisions with recipients
Prior to any onward transfer, MedGuide shall enter into a written agreement with the recipient concerned. This agreement shall contain at least the following provisions:
  • Purpose limitation: the recipient may use the provided data exclusively for the specific, agreed-upon purpose (e.g., the concrete research) and for no other purpose.
  • Prohibition on re-identification: the recipient is expressly prohibited from attempting to identify data subjects, combining the data with other files or sources for the purpose of re-identification, or reversing or breaking the applied pseudonymization or anonymization technique (reverse engineering).
  • Security requirements: the recipient shall implement appropriate technical and organizational measures that are at least equivalent to the level applied by MedGuide itself under Article 5 of the Data Processing Agreement and Article 32 GDPR.
  • Right of audit: MedGuide reserves the right to verify compliance with the agreed obligations, either itself or through an independent third party, with a regular frequency of at least once every two years and furthermore in the event of reasonable cause.
  • Prohibition on further onward transfer: the recipient may not provide or sub-license the data to any other party without the prior written consent of MedGuide.
  • Reporting obligation: the recipient shall inform MedGuide immediately, and in any event within 24 hours, if there is a suspicion that the data - despite pseudonymization or anonymization - has nonetheless become traceable to a natural person, or if a security incident occurs.
  • Retention and destruction period: the recipient shall not retain the data longer than necessary for the agreed purpose and shall destroy or return the data upon completion of the research, or upon the first written request of MedGuide.
  • Transfer outside the EEA: only permitted if the recipient is established in, or the transfer otherwise takes place to, a country with an adequate level of protection within the meaning of Chapter V GDPR, or if appropriate additional safeguards (such as standard contractual clauses) have been agreed upon.
  • Indemnification and liability: the recipient shall indemnify MedGuide against any damages resulting from non-compliance with the obligations mentioned above.
3. Procedure for periodic review of the anonymization or pseudonymization methodology
Frequency. MedGuide shall evaluate the applied anonymization or pseudonymization methodology at least once a year. An interim review shall take place in the event of (i) a relevant change in the underlying dataset or the analysis process, (ii) relevant developments in the state of the art regarding re-identification risks, or (iii) a concrete signal as referred to in Chapter 4 of this annex.

Responsible officer. The Security Officer of MedGuide is responsible for initiating, executing, and documenting the review, where appropriate in consultation with the Data Protection Officer.

Assessment criteria. The review shall in any case include: a motivated-intruder test (the probability that a motivated third party can achieve re-identification with reasonable effort), an evaluation of the remaining re-identification risk (where applicable based on metrics such as k-anonymity or l-diversity), an assessment of the availability of additional (public) data sources that could potentially enable re-identification in combination with the transferred data, and the consequences of technological developments on the level of protection.

Documentation. The outcome of each review shall be recorded in writing in an assessment report containing the method used, the findings, and any follow-up actions. This report will be provided upon request of the Client or a supervisory authority, in accordance with Article 3.1 sub C of the Data Processing Agreement.

Follow-up actions. If the review shows that the methodology used no longer provides an appropriate level of protection, the onward transfer to the recipient category/categories concerned shall be suspended immediately until the methodology has been adjusted and re-validated.
4. Escalation procedure in case of suspicion that transferred data has nonetheless proven to be traceable
Step 1 - Notification and immediate suspension. Any internal or external notification of a suspicion of traceability shall be reported immediately, and at the latest within 24 hours of detection, to the Security Officer via security@themedguidecompany.com. From the moment of notification, any further onward transfer of the dataset concerned to the recipient(s) involved shall be suspended immediately.

Step 2 - Initial assessment. The Security Officer, in cooperation with relevant technical experts, shall assess within 48 hours of notification whether the suspicion is well-founded and whether there is indeed (potential) traceability of natural persons.

Step 3 - Qualification as a data breach. If the suspicion is found to be well-founded, this shall qualify as a personal data breach (data breach) within the meaning of Article 6 of the Data Processing Agreement. The regular notification obligation for data breaches — notification to the Client within 48 hours after discovery, using the form in Annex 2 — remains fully applicable.

Step 4 - Remedial measures. MedGuide shall take appropriate measures without delay to prevent further traceability. Depending on the nature of the incident, this may include: having the data destroyed by the recipient concerned, tightening the anonymization or pseudonymization methodology in accordance with Chapter 3 of this annex, and informing other recipients of any additional obligations.

Step 5 - Documentation and aftercare. The entire incident, including the steps taken, the recipient(s) involved, and the outcome of the investigation, shall be documented and recorded in MedGuide's data breach register. Where necessary, the agreement with the recipient concerned shall be amended, suspended, or terminated.

This document was last updated on July 15, 2026.