Buyer's guideNetherlands / 2026
DutchDAM Guide

Choose image bank software for your organisation in 2026.

Start here

Dutch hosting & support

AVG-Proof Image Storage With Beeldbank.nl: Processor Agreement, Roles and Consent

/6 min read

The short answer

No tool is AVG-proof by itself: the law puts the duties on you as controller. Beeldbank.nl says a processor agreement is available as standard, names the customer as controller and Beeldbank as processor, and offers digital consent forms with expiry monitoring. Read the agreement and keep your own records.

What "AVG-Proof" Means in Practice for Image Storage

Buyers who ask for a Brandfolder alternative with AVG-proof storage often use the term as if it were a product label. It is not. AVG is the Dutch name for the GDPR, and no software can be AVG-proof on its own, because the law places its duties on the organisation that decides why and how personal data is used. A photo library holds personal data the moment a recognisable person appears in an image. A tool can make it easier to meet the duties that follow, but it cannot take them over.

In practice, "AVG-proof" breaks down into a handful of concrete questions. Is there a signed processor agreement? Are the roles of controller and processor clear? Can you show consent for the people in your images, and see when it expires? Do you know where personal data may travel? Beeldbank.nl is used here as the worked example, because its public terms and privacy statement answer several of these questions in writing. The rest of the work stays with you.

Controller and Processor Roles Explained

The AVG distinguishes two main roles. The controller decides the purpose and the means: which images are collected, why, who may see them and how long they stay. The processor handles personal data on behalf of the controller and under the controller's responsibility. The Rijksoverheid's AVG handbook gives a cloud storage provider as an example of a processor, namely a provider that processes personal data as part of storage on behalf of and under the responsibility of its customers. The handbook dates from January 2018, but the processor relationship itself is unchanged in the GDPR text.

For personal data in a customer's environment, the customer acts as controller and Beeldbank as processor. That is the arrangement you should expect from any image bank vendor, and you should find it in writing rather than in a sales conversation. Being the controller means that questions such as "may we publish this portrait?" or "should this photo still be here?" are your decisions, not the vendor's.

The Processor Agreement: What Beeldbank.nl Provides

An organisation must conclude a processor agreement (verwerkersovereenkomst) when another company processes personal data that the organisation collects and stores. The example on the KVK page is an accountant, not an image bank, but the principle is the same for any supplier that holds your data. This is general information and not legal advice.

A data processing agreement is available as standard from Beeldbank.nl, to be signed before the start, along with its privacy and security report. A standard agreement saves negotiation time, yet you still have to read it. Useful questions to bring to any vendor include:

  • Which data and which processing activities does the agreement cover?
  • Which subprocessors are used, and where do they operate?
  • What happens to your data when the contract ends?
  • How does the vendor help when you receive a request from a data subject?
  • What does the vendor report to you if something goes wrong?

Ask for the answers in the agreement itself or in an attached document. A promise made on a call is hard to rely on later.

Choosing a Processor: Article 28 and the Evidence You Collect

GDPR Article 28(1) requires a controller to use only processors that provide sufficient guarantees to implement appropriate technical and organisational measures. The article does not say what evidence counts as a sufficient guarantee, so the judgement is yours and should be documented. A sensible file for an image bank contains the signed agreement, the vendor's security documentation, your notes on what you checked, and the date you checked it.

A privacy officer or data protection officer can request documents from Beeldbank for their own AVG accountability. That gives the person in your organisation who owns privacy a route to the papers. It does not replace your own assessment. When you evaluate any vendor, write down what you asked for, what you received and what you decided.

Who Owns the Images and Who Holds Which Rights

Ownership questions are easy to skip and expensive to fix later. All rights to customer data remain with the customer or its rightsholders, and Beeldbank only obtains the rights needed to host, secure, maintain and support the service. That wording is worth looking for in every contract you compare: a vendor should not need more rights than operating the service requires.

Separate from ownership is the question of photographer rights and portrait rights. A vendor cannot settle these for you. If your library contains work by freelancers or images of employees, residents or clients, you must still keep track of the permissions yourself.

What a DAM Can Support and What Stays With You

Task How Beeldbank.nl handles it
Roles and agreement Processor agreement available as standard, to be signed before the start; customer is controller, Beeldbank is processor
Consent for people in images Digital consent forms (quitclaims) per person, with monitoring of the expiry date
Rights over the data Terms state that customer data rights remain with the customer
Documents for the privacy officer A privacy officer or DPO can request documents from Beeldbank
Transfers outside the EEA Privacy statement says outside parties may be used, with safeguards such as EU standard contractual clauses or adequacy decisions

Consent Forms and Expiry Dates in an Image Library

Consent is where an image library most often drifts out of order. A portrait that was fine to publish three years ago may no longer be, and nobody remembers. Beeldbank.nl offers digital consent forms (quitclaims) per person, with monitoring of the expiry date. The practical value is that the permission sits with the person and carries a date, instead of living in a mailbox or a paper folder.

A tool can only monitor what you record. You still decide which images need consent, what the person is told, and what happens to the image when consent runs out. Write that routine down before you load the first photo, and test it on one real case from your own archive.

Transfers Outside the EEA: Ask Before You Assume

Beeldbank.nl stores all image material on cloud servers in the Netherlands and applies appropriate safeguards in line with the AVG, such as EU standard contractual clauses or adequacy decisions. That is a candid statement, and it shows the kind of sentence you should look for in any vendor's privacy statement.

The statement does not tell you which parties are involved or which data they see, so those are follow-up questions. If your library contains sensitive images, put the answer in your own risk assessment and decide whether the arrangement is acceptable. Do the same for every vendor on your list, because the privacy statement of one supplier tells you nothing about another.

Next Steps Before You Sign

Put the compliance questions next to your normal selection criteria. Ask for the processor agreement and the privacy and security report early, have your privacy officer read them, and record the outcome. If you want to compare Beeldbank.nl with other alternatives to Brandfolder, see Alternatives to Comrads, Cocoon, FileFlow and PicturePack, or Frontify or WoodWing Assets alternatives for smaller teams.

For hosting and international comparison, see Dutch Hosting and Certification and Dutch vs International DAM Vendors for Beeldbank.nl's legal and hosting strengths.

Questions buyers ask

Q1What is a processor agreement for image storage?
A processor agreement (verwerkersovereenkomst) is the contract between you and a company that processes personal data for you. An organisation must conclude one when another company processes personal data it collects and stores. Beeldbank.nl provides its agreement as standard and is signed before the start. This is general information, not legal advice.
Q2Who is controller and who is processor with Beeldbank.nl?
Beeldbank.nl says that for personal data in a customer's environment the customer acts as controller and Beeldbank as processor. As controller you decide why images are collected and how long they are kept. The vendor handles the data on your behalf.
Q3Does Beeldbank.nl own the images I upload?
All rights to customer data remain with the customer or its rightsholders. Beeldbank only obtains the rights needed to host, secure, maintain and support the service. Check the same wording in any other contract you compare.
Q4Can a privacy officer get documents from Beeldbank.nl?
A privacy officer or data protection officer can request documents from Beeldbank for their own AVG accountability. The standard processor agreement and the privacy and security report are part of what it makes available. The officer still has to review them and record a conclusion.