Skip to main content
Review and revision metadata
Review Date: 2026-08-26
Reviewer: Business Manager

previous version on gdrive

ARBIT 2022

1. Corporate Contractual Standardization​

To ensure interoperability, uniform data governance, and rapid onboarding between platform tenants, anDREa B.V. (hereafter referred to as "anDREa") mandates a standardized legal baseline for all IT procurement, software-as-a-service (SaaS) agreements, and client service-level agreements.

  • Primary Framework Baseline: anDREa formally adopts the Arbit 2022 (Algemene Rijksvoorwaarden voor het inkopen van IT-diensten / General Government Terms and Conditions for IT Contracts 2022) as its foundational baseline for corporate Terms & Conditions.
  • Regulatory Compliance Mapping: The uniform application of this framework satisfies ISO/IEC 27001:2023 Control A.05.19 (Information security in supplier relationships) and the EU NIS 2 Directive regarding standardized supply chain risk management and legal predictability.

See: Certificate of Insurance - Liability Insurance


2. Regulatory Amendments & Contractual Deviations​

Effective: 2026-08-26

While anDREa aligns its standard operations with the ARBIT 2022 framework, specific structural and corporate liabilities require explicit deviations. The following clauses replace, supersede, or invalidate the default ARBIT 2022 provisions:

2.1 Incident Reporting & Audits (Article 17 Deviation)​

  • Amended Clause:

In deviation from Article 17 of ARBIT 2022, in the event of a cyber incident, anDREa B.V. will manage incident response and evidence collection through its appointed Cyber Incident Response Manager. Disclosure of detailed incident evidence to the Client is subject to limitations imposed by law, law enforcement, or court orders.

2.2 Personnel Substitution and Operational Continuity (Article 22 Deviation)​

  • Exclusion of Default Clauses: The default provisions of Articles 22.1 and 22.2 of the ARBIT 2022 framework are formally excluded and do not apply to agreements executed by anDREa.
  • Amended Clause:

anDREa B.V. retains the absolute right to replace any personnel or contractors charged with the execution and implementation of the Agreement at its sole discretion. The Client cannot refuse or delay the deployment of such replacement personnel.

2.3 Security & Data Protection (Article 25 Deviation)​

  • Amended Clause:

In deviation from Article 25 of ARBIT 2022, anDREa B.V.’s liability for security incidents is conditional upon the Client maintaining proper system hygiene (including applying critical software updates within 45 days). Liability for widespread zero-day or supply-chain exploits is limited to the extent covered by anDREa’s active insurance policy.

2.4 Liability Caps (Article 26 Deviation)​

  • Amended Clause:

Notwithstanding Article 26 of ARBIT 2022, any aggregate financial liability of anDREa B.V. arising from or connected to data breaches, cyber incidents, privacy violations, or regulatory claims is strictly limited to EUR 1,000,000.- per calendar year, fully subject to the sub-limits and coverage conditions set by anDREa's insurer.

2.5 Insurance (Article 29 Deviation)​

  • Amended Clause:

Notwithstanding Article 29 of ARBIT 2022, anDREa B.V. maintains Professional Liability insurance capped at EUR 1,250,000.- per claim / EUR 2,500,000.- per policy term, and Cyber Liability insurance capped at EUR 1,000,000.- per claim/policy term, in accordance with policy NLINTA25697.