Saltar al contenido principal
Back to blog
Data protectionCollaboration

Data transfer agreements between municipalities for AI projects

July 25, 20265 min readOptimTech
Share:

Why a data transfer agreement is essential for municipal AI projects

More and more municipalities want to develop AI services in collaboration (shared models, joint analysis, federated learning). But exchanging data between public entities without clear rules creates legal, technical and operational risks: GDPR breaches, security failures under the ENS (Royal Decree 311/2022), loss of traceability, or disputes over uses and responsibilities.

A well-designed transfer agreement protects the parties, speeds up projects and facilitates audits. Here is a practical guide with the minimum elements it should contain and an operational process to approve and implement it.

Mandatory and recommended elements of the agreement

1. Clear parties and roles

  • Identify the signing entities and specify roles: data controller, processor or joint controllers. This designation determines obligations and liabilities under the GDPR.
  • Include contact details for the Data Protection Officer (DPO) and the technical lead.

2. Purpose and legal basis

  • Specify the concrete purpose of the exchange (e.g., training models to predict urban incidents).
  • Cite the applicable legal basis under the GDPR (public interest, performance of a public task, etc.) and limit use to that purpose. Avoid open-ended clauses that allow future uses without an additional legal basis.

3. Minimization, pseudonymization and anonymization

  • Require the application of minimization techniques: only the attributes strictly necessary.
  • Prioritize pseudonymization; deliver anonymized data whenever possible.
  • Define acceptable thresholds and techniques (hashing, tokenization, aggregation), and require technical validation before delivery.

4. Security measures and ENS compliance

  • Explicitly reference compliance with the ENS (Royal Decree 311/2022) and require proportional measures: access control, encryption in transit and at rest, key management, audit logging and continuity plans.
  • Include minimum hosting requirements (on-premises or certified cloud) and conditions for subcontracted providers.

5. DPIA and risk assessment

  • Require performing and sharing a Data Protection Impact Assessment (DPIA) before the exchange, with explicit mitigation measures.
  • Establish who leads the DPIA and the procedure to incorporate recommendations.

6. Citizens' rights and responding to requests

  • Define operational procedures to handle access, rectification and erasure requests arising from shared data.
  • Determine responsibilities for these tasks according to the assigned roles.

7. Traceability, audit and transparency

  • Require records of processing activities and availability of logs for audit (frequency and format).
  • Include an obligation to produce documentation for compliance with the Register of AI Systems (where applicable under the EU AI Act).

8. Model governance and use of outputs

  • Clarify what can be done with resulting models (e.g., shared use, commercialization, open release) and conditions for retraining with new data.
  • Require model cards and data sheets documenting biases, limitations and performance metrics.

9. Retention, deletion and reversibility

  • Define retention periods and technical procedures for secure deletion or return of data at the end of the project.
  • Include a portability clause and an exit plan (export of models, audit data).

10. Incidents, liabilities and indemnities

  • Require notification of incidents to the other parties and to the DPO within defined timeframes.
  • Establish liabilities for breaches, indemnity criteria and applicable jurisdiction.

Operational process in 8 practical steps

  1. Initial inventory: table of attributes, sensitivity, sources and volume.
  2. Role decision: appoint controller(s) and processor(s).
  3. Joint DPIA: led by the entity acting as the main controller.
  4. Technical definition: file formats, pseudonymization methods, secure delivery channel.
  5. Drafting the agreement with minimum clauses (see above).
  6. Limited pilot: anonymized datasets and results in a controlled environment.
  7. Audit and acceptance: review the pilot, run security tests and obtain approval from the technical committee.
  8. Operation and monitoring: continuous logs, quarterly reviews and an expiration plan.

Short example clauses (suggested wording)

  • "The parties act as joint controllers with respect to the transferred data for the described purpose and will assume the obligations established by the GDPR."
  • "The data to be transferred will be pseudonymized and encrypted; the key will be managed exclusively by Entity X."
  • "Prior to any transfer, the DPIA will be completed and approved; findings and mitigating measures will form an integral part of this agreement."
  • "In the event of a security incident affecting the transferred data, the affected party will notify the other parties and the DPO within a maximum of 72 hours."

Recommended action plan (24/90/180 days)

  • 24 days: convene a technical meeting among interested municipalities and prepare a data inventory.
  • 90 days: have a minimum viable agreement signed + DPIA approved and a pilot in a controlled environment.
  • 180 days: operational deployment with monitoring, audit and a defined exit plan.

A well-designed agreement accelerates innovation and reduces legal and technical risks. If your team needs templates or help with the DPIA and ENS requirements, solutions like OptimGov Ready can be integrated into your diagnostic and roadmap process without replacing your legal responsibilities. Key action: draft today a minimum viable agreement that includes a DPIA, ENS measures and reversibility clauses.