Ga naar de hoofdinhoud

B_02.02 Contractual arrangements – Specific information

Waarvoor dit template is

B_02.02 bevat de details van elke overeenkomst: welke entiteit welke dienst van welke aanbieder gebruikt, voor welke functie, waar de dienst wordt geleverd en waar de gegevens worden opgeslagen en verwerkt. Het is het meest verbonden template: het verwijst naar B_02.01, B_01.02, B_05.01 en B_06.01.

Invullen

  • Vul eerst B_01.02, B_05.01, B_06.01 en B_02.01; dit template hergebruikt hun identificatiecodes.
  • Sleutelvelden zijn nooit leeg. Het land van dienstverlening (0130), de opslaglocatie (0150) en de verwerkingslocatie (0160) horen bij de sleutel, dus elk veld heeft een waarde nodig.
  • Land van dienstverlening (0130): ondersteunt de ICT-dienst geen kritieke of belangrijke functie, gebruik dan de code "Not applicable" uit de lijst (EBA-FAQ Q59). Dat is zo als de beoordeling van kritiek of belang van de functie in B_06.01 (0050) Nee is. Anders vult u het land van dienstverlening in.
  • Opslaglocatie (0150): is opslag van gegevens (0140) Nee, gebruik dan de code "Not applicable" uit de lijst (EBA-FAQ Q61).
  • Verwerkingslocatie (0160): voorziet de dienst niet in gegevensverwerking, gebruik dan de code "Not applicable" uit de lijst (EBA-FAQ Q63).
  • Gevoeligheid van gegevens (0170) is uw eigen beoordeling; u kunt die toelichten in B_99.01 (EBA-FAQ Q67).

Verduidelijkingen van de AFM

Uit de vragen en antwoorden van de AFM na haar Q&A-sessie van maart 2026 (AFM Q&A (opent in een nieuw tabblad)):

  • Einddatum (0080): vul die in als het contract een vooraf bepaalde einddatum heeft. Heeft het die niet, vul dan 9999-12-31 in. Beëindigde contracten hoeven niet meer te worden opgenomen.
  • Opslag- en verwerkingslocatie: alleen een van de beschikbare opties is toegestaan; "EU" niet. Is het land onbekend, kies dan het land dat het meest in de buurt komt; dat heeft geen invloed op de acceptatie. Een leeg veld leidt tot afwijzing. Vindt er geen opslag plaats, kies dan "not applicable".

Hoe DORA Convert ermee omgaat

Ons Excel-template heeft een tabblad met de naam van dit template. Bij elke kolomkop staat een notitie met wat u invult, een voorbeeld en de officiële bron. Keuzecellen tonen elke optie als omschrijving met de EBA-code; het pakket bevat de code. Fouten blokkeren het pakket, waarschuwingen niet. Zie wat we controleren.

  • Einddatum: verplicht en gecontroleerd als datum. 9999-12-31 wordt geaccepteerd zoals elke geldige datum, en de datumcellen van het template staan die toe.
  • Locaties: een leeg land van dienstverlening, lege opslaglocatie of lege verwerkingslocatie is een fout. Is opslag van gegevens Nee, dan is een andere opslaglocatie dan "Not applicable" een fout. Is de functie in B_06.01 beoordeeld als niet kritiek of belangrijk, dan is een ander land van dienstverlening dan "Not applicable" een fout. We zoeken de functie op via de functie-identificatie en de LEI van de entiteit. Is de functie kritiek of belangrijk en staat het land van dienstverlening op "Not applicable", dan krijgt u een waarschuwing. De verwerkingslocatie controleren we alleen aan de waardelijst.
  • Contract: de referentie moet in B_02.01 bestaan; het datamodel noemt deze koppeling uitdrukkelijk, dus een gebroken koppeling is een fout.
  • Entiteit, aanbieder en functie: verwijzingen die ontbreken in B_01.02, B_05.01 of B_06.01 zijn waarschuwingen, omdat het datamodel het doeltemplate niet noemt. De AFM wijst ze wel af met foutcode 807; los ze op voordat u indient. Een functie-identificatie die in B_06.01 alleen bij een andere LEI bestaat, is een fout.
  • Ondertekenaars: vult u B_03.02 in, dan moet elke combinatie van contract en aanbieder hier daar ook staan; een ontbrekende combinatie is een fout.
  • Sleutels: geen twee regels mogen dezelfde combinatie van sleutelvelden hebben.
  • EBA-regels: de actieve bedrijfsregels van de EBA voor dit template draaien als waarschuwing.

Officiële velden

Officiële samenvatting: Lists the specific information about each contractual arrangement. (ITS Annex I Part 1)

KolomOfficieel labelGegevenstypeSleutel of verwijzingVerplichtToegestane waarden
c0010Contractual arrangement reference numbervarchar(255)PK; FK -> B_02.01Not nullIdentifier value as instructed by ITS/DM
c0020LEI of the entity making use of the ICT service(s)char(20)PK; FK -> B_01.02Not nullLEI identifier; DM field plus relevant LEI business checks where applicable
c0030Identification code of the ICT third-party service providervarchar(255)PK; FK -> B_05.01Not nullIdentifier value as instructed by ITS/DM
c0040Type of code to identify the ICT third-party service providervarchar(255)NullableClosed set; PV B0202/LISTIDTYPE
c0050Function identifiervarchar(255)PK; FK -> B_06.01Not nullIdentifier value as instructed by ITS/DM
c0060Type of ICT servicesvarchar(255)PKNot nullClosed set; PV B0202/LISTSERVICE
c0070Start date of the contractual arrangementdateNot nullDate; ITS/DM require format yyyy-mm-dd
c0080End date of the contractual arrangementdateNot nullDate; ITS/DM require format yyyy-mm-dd
c0090Reason of the termination or ending of the contractual arrangementvarchar(255)NullableClosed set; PV B0202/LISTB02020090
c0100Notice period for the financial entity making use of the ICT service(s)intNullableInteger; TC rule 331 applies
c0110Notice period for the ICT third-party service providerintNullableInteger; TC rule 331 applies
c0120Country of the governing law of the contractual arrangementchar(2)NullableClosed set; PV B0202/LISTCOUNTRY
c0130Country of provision of the ICT serviceschar(2)PKNot nullClosed set; PV B0202/LISTCOUNTRY
c0140Storage of databitNullableClosed set; PV B0202/LISTB02020140
c0150Location of the data at rest (storage)char(2)PKNot nullClosed set; PV B0202/LISTCOUNTRY
c0160Location of management of the data (processing)char(2)PKNot nullClosed set; PV B0202/LISTCOUNTRY
c0170Sensitiveness of the data stored by the ICT third-party service providervarchar(255)NullableClosed set; PV B0202/LISTB02020170
c0180Level of reliance on the ICT service supporting the critical or important function.varchar(255)NullableClosed set; PV B0202/LISTB02020180

Uit het datamodel en de validatieregels van de EBA, zoals vastgelegd op 10 maart 2026. Officiële labels zijn Engelstalig.

Officiële verduidelijkingen

  • c0130 Country of provision of the ICT services: FAQ Q59: this primary-key field cannot be empty; if the ICT service does not support a critical or important function, use the closed-set "Not Applicable" option. FAQ Q59 identifies that case as the function's criticality assessment being "No", citing it as B_06.01.0060 in the ITS numbering; FAQ Q46 maps that field to B_06.01.0050 in the reporting package. The function is the B_06.01 row with the same function identifier and entity LEI.
  • c0150 Location of the data at rest (storage): FAQ Q61: if storage of data = No, use the closed-set "Not Applicable" option.
  • c0160 Location of management of the data (processing): FAQ Q63: if the ICT service does not foresee data processing, use the closed-set "Not Applicable" option.
  • c0170 Sensitiveness of the data stored by the ICT third-party service provider: FAQ Q67: the financial entity defines data sensitivity internally and may explain that assessment in B_99.01.

EBA-validatieregels

Officiële toelichting: Mixture of active and explicitly inactive DORA rules. (VR table B_02.02)

Actieve regels

  • e23680_e

    Officiële formule: with {tB_02.02, default:null, interval:false}: not ( isnull ({c0040-0080}) )

    Onze uitleg: Kolommen c0040 tot en met c0080 moeten in elke rij zijn ingevuld: type code van de aanbieder, functie-ID, type ICT-diensten, begindatum en einddatum. Dat geldt ook voor "Type of code to identify the ICT third-party service provider" (c0040), die in de veldenlijst als optioneel (nullable) staat.
  • v8869_m

    Officiële formule: with {tB_02.02, default: null, interval: false}: if ( not ( isnull ({c0070}) ) ) or not (( isnull ({c0080}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) or not (( isnull ({c0140}) )) or not (( isnull ({c0170}) )) or not (( isnull ({c0180}) )) then ( ( not ( isnull ({c0040}) ) )) endif

    Onze uitleg: Als een andere kolom uit c0040, c0070 tot en met c0120, c0140, c0170 en c0180 is ingevuld, moet ook "Type of code to identify the ICT third-party service provider" (c0040) zijn ingevuld. Kies in c0040 het type code.
  • v8870_m

    Officiële formule: with {tB_02.02, default: null, interval: false}: if ( not ( isnull ({c0040}) ) ) or not (( isnull ({c0080}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) or not (( isnull ({c0140}) )) or not (( isnull ({c0170}) )) or not (( isnull ({c0180}) )) then ( ( not ( isnull ({c0070}) ) )) endif

    Onze uitleg: Als een andere kolom uit c0040, c0070 tot en met c0120, c0140, c0170 en c0180 is ingevuld, moet ook "Start date of the contractual arrangement" (c0070) zijn ingevuld. Vul in c0070 de begindatum in.
  • v8871_m

    Officiële formule: with {tB_02.02, default: null, interval: false}: if ( not ( isnull ({c0070}) ) ) or not (( isnull ({c0040}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) or not (( isnull ({c0140}) )) or not (( isnull ({c0170}) )) or not (( isnull ({c0180}) )) then ( ( not ( isnull ({c0080}) ) )) endif

    Onze uitleg: Als een andere kolom uit c0040, c0070 tot en met c0120, c0140, c0170 en c0180 is ingevuld, moet ook "End date of the contractual arrangement" (c0080) zijn ingevuld. Vul in c0080 de einddatum in.

Inactieve regels

  • v8816_m

    Officiële formule: with {tB_02.02, default: 0, interval: false}: {c0080} > {c0070}

    Onze uitleg: De EBA heeft deze regel op inactief gezet. Zoals hij er staat, eist hij dat "End date of the contractual arrangement" (c0080) later ligt dan "Start date of the contractual arrangement" (c0070); zolang hij inactief is, hoeft u niets te wijzigen.
  • v8893_m

    This VR checks the format of column 0020 (LEI code)

    Officiële formule: match({tB_02.02, c0040}[get LES], "^[A-Z0-9]{18}[0-9]{2}$")

    Onze uitleg: De EBA heeft deze regel op inactief gezet. Hij controleert of de LEI in "LEI of the entity making use of the ICT service(s)" (c0020) de vorm van een LEI heeft (20 tekens: 18 hoofdletters of cijfers, gevolgd door twee cijfers).

De regelteksten komen uit het werkboek met validatieregels van de EBA, zoals vastgelegd op 10 maart 2026. De EBA schrijft de meeste regels alleen als formule, in het Engels. "Onze uitleg" is onze eigen lezing van de regel, geen tekst van de EBA; bij verschil geldt de officiële tekst.

Bronnen

  1. EBA: Preparations for reporting of DORA registers of information (opent in een nieuw tabblad)
  2. EBA: DORA RoI reporting FAQ (28 maart 2025) (opent in een nieuw tabblad)
  3. EBA: Data Model for DORA RoI (opent in een nieuw tabblad)
  4. AFM: Uitvraag informatieregister (opent in een nieuw tabblad)
  5. AFM: Vragen en antwoorden na Q&A-sessie maart 2026 (pdf) (opent in een nieuw tabblad)