Skip to main content

B_02.02 Contractual arrangements – Specific information

What this template is for

B_02.02 holds the detail of each arrangement: which entity uses which service from which provider, for which function, where the service is provided and where the data is stored and processed. It is the most connected template: it refers to B_02.01, B_01.02, B_05.01 and B_06.01.

Filling it in

  • Fill B_01.02, B_05.01, B_06.01 and B_02.01 first; this template reuses their identifiers.
  • Key fields are never empty. The country of provision (0130), the storage location (0150) and the processing location (0160) are part of the key, so each needs a value.
  • Country of provision (0130): where the ICT service does not support a critical or important function, use the closed-set "Not applicable" code (EBA FAQ Q59). That is the case when the function's criticality assessment in B_06.01 (0050) is No. Otherwise, report the country of provision.
  • Storage location (0150): where storage of data (0140) is No, use the closed-set "Not applicable" code (EBA FAQ Q61).
  • Processing location (0160): where the service involves no data processing, use the closed-set "Not applicable" code (EBA FAQ Q63).
  • Data sensitivity (0170) is your own assessment; you can explain it in B_99.01 (EBA FAQ Q67).

AFM clarifications

From the AFM's Q&A after its session of March 2026 (AFM Q&A (opens in a new tab)):

  • End date (0080): fill it in when the contract has a set end date. When it has none, enter 9999-12-31. Contracts that have ended no longer need to be reported.
  • Storage and processing location: only a value from the list is allowed; "EU" is not. If you don't know the country, choose the most likely one; that does not affect acceptance. A blank field causes a rejection. If no data is stored, choose "not applicable".

How DORA Convert handles it

Our Excel template has a sheet named after this template. Each column header carries a note with what to enter, an example and the official source. Drop-down cells show each option as a label with its EBA code; the package carries the code. Errors block the package; warnings do not. See what we check.

  • End date: required and checked as a date. 9999-12-31 is accepted like any valid date, and the template's date cells allow it.
  • Locations: a blank country of provision, storage or processing location is an error. When storage of data is No, a storage location other than "Not applicable" is an error. When the function is assessed as not critical or important in B_06.01, a country of provision other than "Not applicable" is an error. We find the function by its identifier and entity LEI. When the function is critical or important and the country of provision is "Not applicable", you get a warning. The processing location is checked against the value list only.
  • Contract: the reference must exist in B_02.01; this link is stated in the data model, so a broken one is an error.
  • Entity, provider and function: references missing from B_01.02, B_05.01 or B_06.01 are warnings, because the data model does not name those target tables. The AFM still rejects them as error 807, so fix them before you file. A function identifier that exists in B_06.01 only for a different entity LEI is an error.
  • Signatories: if you fill in B_03.02, every contract and provider pair here must appear there; a missing pair is an error.
  • Keys: no two rows may share the same combination of key fields.
  • EBA rules: the EBA's active business rules for this template run as warnings.

Official fields

Official summary: Lists the specific information about each contractual arrangement. (ITS Annex I Part 1)

ColumnOfficial labelData typeKey or referenceRequiredAllowed values
c0010Contractual arrangement reference numbervarchar(255)PK; FK -> B_02.01Not nullIdentifier value as instructed by ITS/DM
c0020LEI of the entity making use of the ICT service(s)char(20)PK; FK -> B_01.02Not nullLEI identifier; DM field plus relevant LEI business checks where applicable
c0030Identification code of the ICT third-party service providervarchar(255)PK; FK -> B_05.01Not nullIdentifier value as instructed by ITS/DM
c0040Type of code to identify the ICT third-party service providervarchar(255)NullableClosed set; PV B0202/LISTIDTYPE
c0050Function identifiervarchar(255)PK; FK -> B_06.01Not nullIdentifier value as instructed by ITS/DM
c0060Type of ICT servicesvarchar(255)PKNot nullClosed set; PV B0202/LISTSERVICE
c0070Start date of the contractual arrangementdateNot nullDate; ITS/DM require format yyyy-mm-dd
c0080End date of the contractual arrangementdateNot nullDate; ITS/DM require format yyyy-mm-dd
c0090Reason of the termination or ending of the contractual arrangementvarchar(255)NullableClosed set; PV B0202/LISTB02020090
c0100Notice period for the financial entity making use of the ICT service(s)intNullableInteger; TC rule 331 applies
c0110Notice period for the ICT third-party service providerintNullableInteger; TC rule 331 applies
c0120Country of the governing law of the contractual arrangementchar(2)NullableClosed set; PV B0202/LISTCOUNTRY
c0130Country of provision of the ICT serviceschar(2)PKNot nullClosed set; PV B0202/LISTCOUNTRY
c0140Storage of databitNullableClosed set; PV B0202/LISTB02020140
c0150Location of the data at rest (storage)char(2)PKNot nullClosed set; PV B0202/LISTCOUNTRY
c0160Location of management of the data (processing)char(2)PKNot nullClosed set; PV B0202/LISTCOUNTRY
c0170Sensitiveness of the data stored by the ICT third-party service providervarchar(255)NullableClosed set; PV B0202/LISTB02020170
c0180Level of reliance on the ICT service supporting the critical or important function.varchar(255)NullableClosed set; PV B0202/LISTB02020180

From the EBA data model and validation rules, as recorded on 10 March 2026. Official labels are in English.

Official clarifications

  • c0130 Country of provision of the ICT services: FAQ Q59: this primary-key field cannot be empty; if the ICT service does not support a critical or important function, use the closed-set "Not Applicable" option. FAQ Q59 identifies that case as the function's criticality assessment being "No", citing it as B_06.01.0060 in the ITS numbering; FAQ Q46 maps that field to B_06.01.0050 in the reporting package. The function is the B_06.01 row with the same function identifier and entity LEI.
  • c0150 Location of the data at rest (storage): FAQ Q61: if storage of data = No, use the closed-set "Not Applicable" option.
  • c0160 Location of management of the data (processing): FAQ Q63: if the ICT service does not foresee data processing, use the closed-set "Not Applicable" option.
  • c0170 Sensitiveness of the data stored by the ICT third-party service provider: FAQ Q67: the financial entity defines data sensitivity internally and may explain that assessment in B_99.01.

EBA validation rules

Official note: Mixture of active and explicitly inactive DORA rules. (VR table B_02.02)

Active rules

  • e23680_e

    Official expression: with {tB_02.02, default:null, interval:false}: not ( isnull ({c0040-0080}) )

    Our explanation: Columns c0040 to c0080 must be filled in every row: provider code type, function identifier, type of ICT services, start date and end date. This includes "Type of code to identify the ICT third-party service provider" (c0040), which the field list marks as nullable.
  • v8869_m

    Official expression: with {tB_02.02, default: null, interval: false}: if ( not ( isnull ({c0070}) ) ) or not (( isnull ({c0080}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) or not (( isnull ({c0140}) )) or not (( isnull ({c0170}) )) or not (( isnull ({c0180}) )) then ( ( not ( isnull ({c0040}) ) )) endif

    Our explanation: When any other column among c0040, c0070 to c0120, c0140, c0170 and c0180 is filled, "Type of code to identify the ICT third-party service provider" (c0040) must be filled too. Choose the code type in c0040.
  • v8870_m

    Official expression: with {tB_02.02, default: null, interval: false}: if ( not ( isnull ({c0040}) ) ) or not (( isnull ({c0080}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) or not (( isnull ({c0140}) )) or not (( isnull ({c0170}) )) or not (( isnull ({c0180}) )) then ( ( not ( isnull ({c0070}) ) )) endif

    Our explanation: When any other column among c0040, c0070 to c0120, c0140, c0170 and c0180 is filled, "Start date of the contractual arrangement" (c0070) must be filled too. Enter the start date in c0070.
  • v8871_m

    Official expression: with {tB_02.02, default: null, interval: false}: if ( not ( isnull ({c0070}) ) ) or not (( isnull ({c0040}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) or not (( isnull ({c0140}) )) or not (( isnull ({c0170}) )) or not (( isnull ({c0180}) )) then ( ( not ( isnull ({c0080}) ) )) endif

    Our explanation: When any other column among c0040, c0070 to c0120, c0140, c0170 and c0180 is filled, "End date of the contractual arrangement" (c0080) must be filled too. Enter the end date in c0080.

Inactive rules

  • v8816_m

    Official expression: with {tB_02.02, default: 0, interval: false}: {c0080} > {c0070}

    Our explanation: The EBA has marked this rule inactive. As written, it requires "End date of the contractual arrangement" (c0080) to be later than "Start date of the contractual arrangement" (c0070); nothing needs changing while it stays inactive.
  • v8893_m

    This VR checks the format of column 0020 (LEI code)

    Official expression: match({tB_02.02, c0040}[get LES], "^[A-Z0-9]{18}[0-9]{2}$")

    Our explanation: The EBA has marked this rule inactive. It checks that the LEI in "LEI of the entity making use of the ICT service(s)" (c0020) has the LEI format (20 characters: 18 capital letters or digits, then two digits).

Rule texts are copied from the EBA validation-rule workbook, as recorded on 10 March 2026. The EBA writes most rules only as a formula, in English. "Our explanation" is our plain-language reading of the rule, not EBA text; where they differ, the official text applies.

Sources

  1. EBA: Preparations for reporting of DORA registers of information (opens in a new tab)
  2. EBA: DORA RoI reporting FAQ (28 March 2025) (opens in a new tab)
  3. EBA: Data Model for DORA RoI (opens in a new tab)
  4. AFM: Register of Information (opens in a new tab)
  5. AFM: Q&A after the Q&A session, March 2026 (PDF) (opens in a new tab)