Under GDPR Art. 28, what must a controller-processor contract contain, and what does it commit the processor to?
answer
- written, binding, describes the processing
- eight stipulations, points (a) to (h)
- instructions, confidentiality, security
- sub-processors flow down
basics
~20 sGDPR Art. 28(3) requires a written, binding contract describing the processing and committing the processor to documented instructions, confidentiality, Art. 32 security, sub-processor rules, assistance with rights and Arts. 32-36, deletion or return at the end, and audits.
solid answer
~50 sUnder GDPR `Art. 28(3)`, processing by a processor must be governed by a contract or other legal act, in writing including electronic form (`Art. 28(9)`), that sets out the subject-matter and duration, nature and purpose, the types of personal data and categories of data subjects, and the controller's rights and obligations. It must stipulate that the processor (a) acts only on **documented instructions**, (b) binds its people to **confidentiality**, (c) takes the **`Art. 32` security** measures, (d) respects the **sub-processor** conditions, (e) helps the controller answer **data-subject requests**, (f) helps with **`Arts. 32-36`**, (g) **deletes or returns** the data at the end, at the controller's choice, and (h) provides compliance information and allows **audits**. Sub-processors need prior written authorisation (`Art. 28(2)`), must receive the same obligations, and the initial processor stays fully liable for them (`Art. 28(4)`).
go deeper
Recall that using a processor requires a written contract under Art. 28, and that it binds the processor to act only on the controller's documented instructions.
List the descriptive items and the eight stipulations in Art. 28(3)(a)-(h), and explain the Art. 28(2) and (4) sub-processor rules, including general authorisation with an objection right.
Review a vendor agreement against Art. 28(3): spot a missing processing description, audit rights reduced to a report, or a sub-processor clause without notice of changes.
Decide how the organisation standardises processor terms, using standard clauses under Art. 28(6)-(8) as a floor while keeping Art. 28(1) due diligence on each vendor meaningful.
## Why the GDPR requires a contract at all A **processor** handles personal data on behalf of a **controller** (`Art. 4(8)`). Because the controller stays accountable for processing it has handed off, `Art. 28(1)` allows it to use only processors *providing sufficient guarantees* of appropriate technical and organisational measures, and `Art. 28(3)` requires the relationship to be governed by a **contract or other legal act** under Union or Member State law that is **binding on the processor** with regard to the controller. `Art. 28(9)` requires it to be **in writing, including in electronic form**, so a click-through data processing agreement can qualify. ## What the contract must describe Before the stipulations, `Art. 28(3)` requires the contract to *set out*: - the **subject-matter and duration** of the processing; - the **nature and purpose** of the processing; - the **type of personal data** and the **categories of data subjects**; - the **obligations and rights of the controller**. A generic agreement that never says what is processed, for whom and why does not meet this. ## The eight stipulations, points (a) to (h) | Point | The processor must... | |---|---| | (a) | process only on **documented instructions** from the controller, including on transfers to a third country, unless Union or Member State law requires otherwise, and then inform the controller first unless that law forbids it | | (b) | ensure that people authorised to process the data are bound by **confidentiality** | | (c) | take all measures required under **`Art. 32`** (security of processing) | | (d) | respect the conditions in `Art. 28(2)` and `(4)` for engaging **another processor** | | (e) | **assist** the controller, as far as possible, in responding to **data-subject rights** requests under Chapter III | | (f) | **assist** the controller with its obligations under **`Arts. 32 to 36`**: security, breach notification and communication, impact assessments and prior consultation | | (g) | at the controller's choice, **delete or return** all personal data at the end of the services and delete existing copies, unless law requires storage | | (h) | make available all **information** needed to demonstrate compliance, and allow for and contribute to **audits**, including inspections, by the controller or its mandated auditor | The article adds one more duty directly after the list: the processor must **immediately inform** the controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions. ## Sub-processors Sub-processing has its own rules: 1. **Authorisation.** A processor may not engage another processor without the controller's **prior specific or general written authorisation** (`Art. 28(2)`). 2. **Notice and objection.** Under a *general* authorisation, the processor must **inform the controller of any intended addition or replacement**, giving it the opportunity to **object** (`Art. 28(2)`). 3. **Flow-down.** The same data protection obligations must be imposed on the sub-processor by contract or other legal act (`Art. 28(4)`). 4. **Liability.** If the sub-processor fails, the **initial processor remains fully liable to the controller** for its performance (`Art. 28(4)`). ## Standard clauses and guarantees The contract need not be drafted from scratch: - `Art. 28(6)` lets it be based wholly or partly on **standard contractual clauses** adopted by the Commission (`Art. 28(7)`) or by a supervisory authority (`Art. 28(8)`). The Commission adopted such clauses in Implementing Decision (EU) 2021/915. - Where a controller transfers data to a processor outside the GDPR's territorial scope, the Commission's transfer clauses in Decision (EU) 2021/914 state that they also fulfil the `Art. 28(3)` and `(4)` requirements for that relationship; the transfer rules themselves are a separate subject. - Adherence to an approved **code of conduct** (`Art. 40`) or **certification** (`Art. 42`) may be used as an element to demonstrate sufficient guarantees (`Art. 28(5)`), not as a substitute for the contract. ## What the contract does not do - It does **not** make the processor a controller or give it any purpose of its own. `Art. 29` repeats that the processor processes only on the controller's instructions. - It does **not** replace the processor's direct statutory duties, such as records of processing (`Art. 30(2)`), `Art. 32` security and notifying the controller of a breach without undue delay (`Art. 33(2)`). - It does **not** protect a processor that goes beyond it: one that determines purposes and means is treated as a controller for that processing (`Art. 28(10)`).
- Under GDPR Art. 28, what must a processor do if it believes an instruction from the controller is unlawful?Immediately inform the controller that, in its opinion, the instruction infringes the GDPR or other Union or Member State data protection provisions. The duty sits in `Art. 28(3)` directly after point (h). It does not let the processor substitute its own purposes; it raises the problem with the party that decides them.
- Under GDPR Art. 28(2), how does a general written authorisation for sub-processors work?The controller authorises sub-processing in general terms instead of approving each one. The processor must then inform the controller of any intended addition or replacement of sub-processors, giving it the opportunity to object. The same obligations flow down under `Art. 28(4)`, and the initial processor stays fully liable for each sub-processor's performance.
saying these in an interview costs you the question
- A processor may bring in any sub-processor it likes without telling the controller.
- An Art. 28 agreement must be a signed paper contract; electronic form is not enough.
- Once the contract ends, the processor may keep the data for its own purposes.
- A security certificate from the vendor replaces the need for an Art. 28 contract.
- If a sub-processor fails, only the sub-processor answers to the controller.