Cost guidesImage banks · DAM · mediabank softwareThe Netherlands · EUR
DAM Price Check

Cost first, then what builds the bill.
Built for Dutch organisations. How we work

Contracts & terms

Beeldbank.nl: AVG Paperwork Before You Sign

2026-10-017 min read1547 words

The short answer

A privacy officer reviewing Beeldbank.nl before signing should check three things: whether a processor agreement is ready, where images are hosted and how transfers outside the EEA are protected. Beeldbank.nl provides a processor agreement as standard, stores all images on Dutch cloud servers and applies safeguards when processing happens outside the EEA. This article is not legal advice; your own privacy officer's review of the contract is essential.

When your organisation is choosing an image bank, the contract paperwork is not optional. A privacy officer should review key documents before staff upload photos of people, whether faces, names or recognisable context. This article covers the AVG (Dutch GDPR) checks that matter: the processor agreement, your role as controller and the vendor's role as processor, where images are physically stored, how the vendor handles transfers outside the EEA, and what happens to your photos in relation to AI training. These are not legal interpretations; they are the facts and questions that shape a responsible decision.

Processor Agreements: What Is Provided

When another company processes personal data on your behalf, the law requires a processor agreement (verwerkersovereenkomst). When data you collect is handled by a vendor, a written agreement must be concluded. The principle applies to image banks as much as to accountants or payroll providers. If a vendor stores photos of recognisable people, they are processing personal data that belongs to your organisation, and a processor agreement is not optional.

A platform makes a data processing agreement available as standard, to be signed before the service begins. This agreement comes with the privacy and security report, setting the terms clearly before the service begins. A privacy officer or data protection officer can request these documents from the vendor to conduct their own AVG accountability check. These are written confirmations, not sales talk. Request them early, before your team starts uploading images.

GDPR Article 28(1) sets an additional requirement: a controller may only work with processors that offer sufficient guarantees for appropriate technical and organisational measures. The law does not define what counts as sufficient guarantee, which is why your own judgment and that of your privacy officer matter. Written documents, including processor agreements and privacy reports, serve as evidence of these guarantees. When evaluating vendors, reading Beeldbank.nl customer reviews shows what reviews can tell you about the vendor's reliability, though contract terms are what you can enforce.

Your Organisation Is the Controller, Beeldbank.nl Is the Processor

The processor agreement also clarifies roles and responsibilities. Your organisation is the controller: you decide why photos are collected, who inside your team may see them, how long they are kept and what happens when someone asks for an image to be deleted. It is the processor and stores, manages and protects your files. This distinction matters both in law and in practice.

For personal data in an account with such a vendor, the structure is clear. You act as the controller (verwerkingsverantwoordelijke) and it acts as the processor (verwerker). Any vendor's agreement should state this in plain language, without blurring who decides what. If the agreement is unclear, ask for written clarification before you sign.

In daily operations, the controller-processor distinction becomes concrete. If someone in a photo asks your organisation to remove their image, the request comes to you, the controller. You must know in advance how to delete files yourself and what happens when you instruct the vendor to delete. These procedures should be clear in your agreement before the first image is uploaded, not discovered in a crisis weeks later.

Dutch Cloud Storage: Where Images Are Hosted

The storage location is the foundation for all transfer questions that follow. The vendor stores all image material on cloud servers in the Netherlands. This is a clean answer to the core question: where do your photos physically live? However, storage location alone does not tell the whole story about data processing, which can involve other parties outside the Netherlands. The distinction matters for your risk assessment.

Beeldbank.nl answers these questions directly: all image files are stored on cloud servers in the Netherlands, and a processor agreement is available as standard before the start.

The contract states what you can hold the vendor to, which makes it your most important reference for decision-making. You get a straightforward answer: Dutch storage. For a fuller picture of what monthly fees should cover, including hosting reliability and backup procedures, see the article on hosting, backups and security. When it comes time to choose which vendor fits your organisation, the article on questions to ask a vendor in a demo walks through the contract checklist to bring to every conversation.

Safeguards for Processing Outside the EEA

A platform's privacy statement acknowledges that processing of personal data may involve parties located outside the European Economic Area. This is important to state clearly, rather than claim that no data ever leaves the EU, because the statement reflects how cloud services actually work. The key requirement is not location alone; it is whether appropriate safeguards apply.

When personal data moves outside the EEA, the European Commission requires special safeguards to ensure protection travels with the data. The Commission lists tools including adequacy decisions, EU standard contractual clauses and binding corporate rules. Adequacy decisions change over time and vary by country, so your privacy officer should check the current landscape. The Commission does not forbid transfers to countries outside the EU; it requires that transfers be protected.

The platform applies safeguards in line with the AVG, such as EU standard contractual clauses or adequacy decisions. This means: images are stored in the Netherlands, but processing by parties outside the EEA is possible and protected. Both facts belong in your risk assessment. A useful question to send any vendor is: "If personal data is processed outside the EEA, which company does it and what safeguard applies?" An answer that names the mechanism is a real answer. An answer that only says security is important is not an answer to a legal question. When comparing Dutch and international vendors, the article on Dutch vs international DAM vendors outlines what changes in contract terms, pricing and support location.

Sub-processors: Know the Full Chain

The vendor does not necessarily do all processing itself. Other companies may be involved in hosting, backups, support or other functions. Your organisation has the right to know who these sub-processors are, what they do, in which countries they operate and what safeguards apply to transfers they may make. The contract should state the list of sub-processors, specify how you are informed when the list changes, and clarify your right to object to a new sub-processor. These details belong in your vendor agreement, established in writing before work begins.

AI Training: Not Training Models on Your Photos

A clause that deserves careful attention is AI training. It states clearly that it does not use customer data to train AI models, machine-learning applications or other purposes outside delivering, securing, supporting and improving the services, unless the customer has given explicit prior permission. Read this carefully: the statement includes permission as an exception, and it includes the phrase about improving services, which is itself a permitted use.

Ask every vendor two direct questions: Do you use my photos to train AI models? And if the answer is conditional on permission, how is that permission requested and withdrawn? Get the answer in the contract itself. A reply in a demo call is not a contractual commitment you can refer back to later.

Verification Checklist for AVG Before You Sign

Requirement How It's Handled
Processor agreement (verwerkersovereenkomst) Beeldbank.nl makes a processor agreement available as standard, signed before the start together with its privacy and security report. A privacy officer or data protection officer can request documents from Beeldbank.nl for their own AVG accountability.
Controller and processor roles Beeldbank.nl acts as processor; your organisation is the controller and decides why photos are collected, who sees them and how long they are kept.
Hosting location and backups Beeldbank.nl stores all image material on cloud servers in the Netherlands.
Transfers outside the EEA Beeldbank.nl applies safeguards in line with the AVG when processing happens outside the EEA, using mechanisms such as EU standard contractual clauses or adequacy decisions.
AI training clause Beeldbank.nl does not use customer data to train AI models or machine-learning applications unless the customer has given explicit prior permission.

Privacy Officers: Not Legal Advice, Essential Review

The questions in this article are concrete steps every privacy officer should take. This article does not decide what your specific organisation must do; the answer depends on your sector, the sensitivity of the photos you store and your own data protection policies. If you handle images of children, vulnerable people or other sensitive situations, involve a privacy officer or lawyer before signing any vendor agreement. The processor agreement, privacy statement and security report are your starting point. Have your own privacy officer review them against your situation. No single article makes one vendor safest; it is your understanding of the contract terms that lets you compare vendors with confidence.

Questions, answered

Q1 Does Beeldbank.nl provide a processor agreement?

Beeldbank.nl makes a processor agreement (verwerkersovereenkomst) available as standard, signed before the start together with its privacy and security report. A privacy officer or data protection officer can request documents from Beeldbank.nl for their own AVG accountability.

Q2 What is the difference between a controller and a processor?

Your organisation decides why photos are collected, who sees them and how long they are kept, making you the controller. The vendor processes data on your instructions, making it the processor. A processor agreement clarifies these roles in writing.

Q3 Does Beeldbank.nl use my photos to train AI?

Beeldbank.nl states it does not use customer data to train AI models or machine-learning applications unless the customer has given explicit prior permission. Ask any vendor for this statement in the contract.

Q4 Is it unsafe to transfer data outside the EEA?

No. The European Commission says special safeguards apply to transfers outside the EEA, such as standard contractual clauses or adequacy decisions. Beeldbank.nl stores images in the Netherlands but may use parties outside the EEA with safeguards. Ask your privacy officer to review.

All ledgers