B_02.02 Contractual arrangements – Specific information
Waarvoor dit template is
B_02.02 bevat de details van elke overeenkomst: welke entiteit welke dienst van welke aanbieder gebruikt, voor welke functie, waar de dienst wordt geleverd en waar de gegevens worden opgeslagen en verwerkt. Het is het meest verbonden template: het verwijst naar B_02.01, B_01.02, B_05.01 en B_06.01.
Invullen
- Vul eerst B_01.02, B_05.01, B_06.01 en B_02.01; dit template hergebruikt hun identificatiecodes.
- Sleutelvelden zijn nooit leeg. Het land van dienstverlening (0130), de opslaglocatie (0150) en de verwerkingslocatie (0160) horen bij de sleutel, dus elk veld heeft een waarde nodig.
- Land van dienstverlening (0130): ondersteunt de ICT-dienst geen kritieke of belangrijke functie, gebruik dan de code "Not applicable" uit de lijst (EBA-FAQ Q59). Dat is zo als de beoordeling van kritiek of belang van de functie in B_06.01 (0050) Nee is. Anders vult u het land van dienstverlening in.
- Opslaglocatie (0150): is opslag van gegevens (0140) Nee, gebruik dan de code "Not applicable" uit de lijst (EBA-FAQ Q61).
- Verwerkingslocatie (0160): voorziet de dienst niet in gegevensverwerking, gebruik dan de code "Not applicable" uit de lijst (EBA-FAQ Q63).
- Gevoeligheid van gegevens (0170) is uw eigen beoordeling; u kunt die toelichten in B_99.01 (EBA-FAQ Q67).
Verduidelijkingen van de AFM
Uit de vragen en antwoorden van de AFM na haar Q&A-sessie van maart 2026 (AFM Q&A (opent in een nieuw tabblad)):
- Einddatum (0080): vul die in als het contract een vooraf bepaalde einddatum heeft. Heeft het die niet, vul dan 9999-12-31 in. Beëindigde contracten hoeven niet meer te worden opgenomen.
- Opslag- en verwerkingslocatie: alleen een van de beschikbare opties is toegestaan; "EU" niet. Is het land onbekend, kies dan het land dat het meest in de buurt komt; dat heeft geen invloed op de acceptatie. Een leeg veld leidt tot afwijzing. Vindt er geen opslag plaats, kies dan "not applicable".
Hoe DORA Convert ermee omgaat
Ons Excel-template heeft een tabblad met de naam van dit template. Bij elke kolomkop staat een notitie met wat u invult, een voorbeeld en de officiële bron. Keuzecellen tonen elke optie als omschrijving met de EBA-code; het pakket bevat de code. Fouten blokkeren het pakket, waarschuwingen niet. Zie wat we controleren.
- Einddatum: verplicht en gecontroleerd als datum. 9999-12-31 wordt geaccepteerd zoals elke geldige datum, en de datumcellen van het template staan die toe.
- Locaties: een leeg land van dienstverlening, lege opslaglocatie of lege verwerkingslocatie is een fout. Is opslag van gegevens Nee, dan is een andere opslaglocatie dan "Not applicable" een fout. Is de functie in B_06.01 beoordeeld als niet kritiek of belangrijk, dan is een ander land van dienstverlening dan "Not applicable" een fout. We zoeken de functie op via de functie-identificatie en de LEI van de entiteit. Is de functie kritiek of belangrijk en staat het land van dienstverlening op "Not applicable", dan krijgt u een waarschuwing. De verwerkingslocatie controleren we alleen aan de waardelijst.
- Contract: de referentie moet in B_02.01 bestaan; het datamodel noemt deze koppeling uitdrukkelijk, dus een gebroken koppeling is een fout.
- Entiteit, aanbieder en functie: verwijzingen die ontbreken in B_01.02, B_05.01 of B_06.01 zijn waarschuwingen, omdat het datamodel het doeltemplate niet noemt. De AFM wijst ze wel af met foutcode 807; los ze op voordat u indient. Een functie-identificatie die in B_06.01 alleen bij een andere LEI bestaat, is een fout.
- Ondertekenaars: vult u B_03.02 in, dan moet elke combinatie van contract en aanbieder hier daar ook staan; een ontbrekende combinatie is een fout.
- Sleutels: geen twee regels mogen dezelfde combinatie van sleutelvelden hebben.
- EBA-regels: de actieve bedrijfsregels van de EBA voor dit template draaien als waarschuwing.
Officiële velden
Officiële samenvatting: Lists the specific information about each contractual arrangement. (ITS Annex I Part 1)
| Kolom | Officieel label | Gegevenstype | Sleutel of verwijzing | Verplicht | Toegestane waarden |
|---|---|---|---|---|---|
| c0010 | Contractual arrangement reference number | varchar(255) | PK; FK -> B_02.01 | Not null | Identifier value as instructed by ITS/DM |
| c0020 | LEI of the entity making use of the ICT service(s) | char(20) | PK; FK -> B_01.02 | Not null | LEI identifier; DM field plus relevant LEI business checks where applicable |
| c0030 | Identification code of the ICT third-party service provider | varchar(255) | PK; FK -> B_05.01 | Not null | Identifier value as instructed by ITS/DM |
| c0040 | Type of code to identify the ICT third-party service provider | varchar(255) | Nullable | Closed set; PV B0202/LISTIDTYPE | |
| c0050 | Function identifier | varchar(255) | PK; FK -> B_06.01 | Not null | Identifier value as instructed by ITS/DM |
| c0060 | Type of ICT services | varchar(255) | PK | Not null | Closed set; PV B0202/LISTSERVICE |
| c0070 | Start date of the contractual arrangement | date | Not null | Date; ITS/DM require format yyyy-mm-dd | |
| c0080 | End date of the contractual arrangement | date | Not null | Date; ITS/DM require format yyyy-mm-dd | |
| c0090 | Reason of the termination or ending of the contractual arrangement | varchar(255) | Nullable | Closed set; PV B0202/LISTB02020090 | |
| c0100 | Notice period for the financial entity making use of the ICT service(s) | int | Nullable | Integer; TC rule 331 applies | |
| c0110 | Notice period for the ICT third-party service provider | int | Nullable | Integer; TC rule 331 applies | |
| c0120 | Country of the governing law of the contractual arrangement | char(2) | Nullable | Closed set; PV B0202/LISTCOUNTRY | |
| c0130 | Country of provision of the ICT services | char(2) | PK | Not null | Closed set; PV B0202/LISTCOUNTRY |
| c0140 | Storage of data | bit | Nullable | Closed set; PV B0202/LISTB02020140 | |
| c0150 | Location of the data at rest (storage) | char(2) | PK | Not null | Closed set; PV B0202/LISTCOUNTRY |
| c0160 | Location of management of the data (processing) | char(2) | PK | Not null | Closed set; PV B0202/LISTCOUNTRY |
| c0170 | Sensitiveness of the data stored by the ICT third-party service provider | varchar(255) | Nullable | Closed set; PV B0202/LISTB02020170 | |
| c0180 | Level of reliance on the ICT service supporting the critical or important function. | varchar(255) | Nullable | Closed set; PV B0202/LISTB02020180 |
Uit het datamodel en de validatieregels van de EBA, zoals vastgelegd op 10 maart 2026. Officiële labels zijn Engelstalig.
Officiële verduidelijkingen
- c0130 Country of provision of the ICT services: FAQ Q59: this primary-key field cannot be empty; if the ICT service does not support a critical or important function, use the closed-set "Not Applicable" option. FAQ Q59 identifies that case as the function's criticality assessment being "No", citing it as B_06.01.0060 in the ITS numbering; FAQ Q46 maps that field to B_06.01.0050 in the reporting package. The function is the B_06.01 row with the same function identifier and entity LEI.
- c0150 Location of the data at rest (storage): FAQ Q61: if storage of data = No, use the closed-set "Not Applicable" option.
- c0160 Location of management of the data (processing): FAQ Q63: if the ICT service does not foresee data processing, use the closed-set "Not Applicable" option.
- c0170 Sensitiveness of the data stored by the ICT third-party service provider: FAQ Q67: the financial entity defines data sensitivity internally and may explain that assessment in B_99.01.
EBA-validatieregels
Officiële toelichting: Mixture of active and explicitly inactive DORA rules. (VR table B_02.02)
Actieve regels
Officiële formule:
Onze uitleg: Kolommen c0040 tot en met c0080 moeten in elke rij zijn ingevuld: type code van de aanbieder, functie-ID, type ICT-diensten, begindatum en einddatum. Dat geldt ook voor "Type of code to identify the ICT third-party service provider" (c0040), die in de veldenlijst als optioneel (nullable) staat.with {tB_02.02, default:null, interval:false}: not ( isnull ({c0040-0080}) )Officiële formule:
Onze uitleg: Als een andere kolom uit c0040, c0070 tot en met c0120, c0140, c0170 en c0180 is ingevuld, moet ook "Type of code to identify the ICT third-party service provider" (c0040) zijn ingevuld. Kies in c0040 het type code.with {tB_02.02, default: null, interval: false}: if ( not ( isnull ({c0070}) ) ) or not (( isnull ({c0080}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) or not (( isnull ({c0140}) )) or not (( isnull ({c0170}) )) or not (( isnull ({c0180}) )) then ( ( not ( isnull ({c0040}) ) )) endifOfficiële formule:
Onze uitleg: Als een andere kolom uit c0040, c0070 tot en met c0120, c0140, c0170 en c0180 is ingevuld, moet ook "Start date of the contractual arrangement" (c0070) zijn ingevuld. Vul in c0070 de begindatum in.with {tB_02.02, default: null, interval: false}: if ( not ( isnull ({c0040}) ) ) or not (( isnull ({c0080}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) or not (( isnull ({c0140}) )) or not (( isnull ({c0170}) )) or not (( isnull ({c0180}) )) then ( ( not ( isnull ({c0070}) ) )) endifOfficiële formule:
Onze uitleg: Als een andere kolom uit c0040, c0070 tot en met c0120, c0140, c0170 en c0180 is ingevuld, moet ook "End date of the contractual arrangement" (c0080) zijn ingevuld. Vul in c0080 de einddatum in.with {tB_02.02, default: null, interval: false}: if ( not ( isnull ({c0070}) ) ) or not (( isnull ({c0040}) )) or not (( isnull ({c0090}) )) or not (( isnull ({c0100}) )) or not (( isnull ({c0110}) )) or not (( isnull ({c0120}) )) or not (( isnull ({c0140}) )) or not (( isnull ({c0170}) )) or not (( isnull ({c0180}) )) then ( ( not ( isnull ({c0080}) ) )) endif
Inactieve regels
Officiële formule:
Onze uitleg: De EBA heeft deze regel op inactief gezet. Zoals hij er staat, eist hij dat "End date of the contractual arrangement" (c0080) later ligt dan "Start date of the contractual arrangement" (c0070); zolang hij inactief is, hoeft u niets te wijzigen.with {tB_02.02, default: 0, interval: false}: {c0080} > {c0070}This VR checks the format of column 0020 (LEI code)
Officiële formule:
Onze uitleg: De EBA heeft deze regel op inactief gezet. Hij controleert of de LEI in "LEI of the entity making use of the ICT service(s)" (c0020) de vorm van een LEI heeft (20 tekens: 18 hoofdletters of cijfers, gevolgd door twee cijfers).match({tB_02.02, c0040}[get LES], "^[A-Z0-9]{18}[0-9]{2}$")
De regelteksten komen uit het werkboek met validatieregels van de EBA, zoals vastgelegd op 10 maart 2026. De EBA schrijft de meeste regels alleen als formule, in het Engels. "Onze uitleg" is onze eigen lezing van de regel, geen tekst van de EBA; bij verschil geldt de officiële tekst.
Bronnen
- EBA: Preparations for reporting of DORA registers of information (opent in een nieuw tabblad)
- EBA: DORA RoI reporting FAQ (28 maart 2025) (opent in een nieuw tabblad)
- EBA: Data Model for DORA RoI (opent in een nieuw tabblad)
- AFM: Uitvraag informatieregister (opent in een nieuw tabblad)
- AFM: Vragen en antwoorden na Q&A-sessie maart 2026 (pdf) (opent in een nieuw tabblad)