Skip to content
compliancebase
GDPRChapter IV — Processor

Article 28

Processor

GDPR · Regulation (EU) 2016/679 · Last verified July 2026

Objective

Where processing is carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees, and processing shall be governed by a contract or other legal act that sets out the subject matter, duration, nature, purpose, types of data, obligations, and the Article 28(3) mandatory terms.

Points of focus

  • Controllers select processors with sufficient guarantees of Article 32-level measures
  • Bind processing to a contract covering Article 28(3) required terms
  • Processors act only on documented instructions unless required by law
  • Flow down equivalent obligations to sub-processors with prior authorisation rules
  • Assist with security, breach notification, DPIAs, and deletion/return at end of service

Implementation notes

Most B2B SaaS companies are processors for customer-uploaded personal data and controllers for their own account and marketing data — Article 28 is the spine of the processor relationship. Maintain a GDPR-ready DPA that includes processing instructions, confidentiality, security measures, sub-processor rules, assistance with data-subject requests, breach cooperation, audit/information rights, and deletion or return at end of service. Diligence new sub-processors (infra, support, AI) before they touch personal data, publish a current sub-processor list, and flow down equivalent terms. Train support and engineering that customer content is processed only on documented instructions — not for unrelated model training or marketing. Pair Article 28 contracts with Article 32 technical measures and transferable evidence (SOC 2, ISO) so 'sufficient guarantees' are both legal and operational.

Audit tip: Produce the DPA template mapped clause-by-clause to Article 28(3), plus one sub-processor onboarding packet (diligence + flow-down + customer notice).

Evidence auditors typically request:

  • Signed DPA / Article 28 addendum with customers (controller) or vendors (your processors)
  • Sub-processor list with notice/objection mechanism
  • Vendor security due diligence records before onboarding processors
  • Instructions register or ticket trail for customer deletion/export requests
  • SOC 2 / ISO reports used as 'sufficient guarantees' support (not a substitute for the contract)

Common gaps

  • MSA without Article 28(3) mandatory processor terms
  • Sub-processors added without contract flow-down or customer notice
  • Using customer data for product R&D outside documented instructions
  • No process to return or delete data after contract end

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 28This control
ISO 27001A.5.19, A.5.20, A.5.21Supplier relationships and ICT supply chain
SOC 2CC9.2Vendor risk management
HIPAA164.308(b), 164.314(a)Business associate agreements — analogous but distinct regime

Primary sources

Frequently Asked Questions

No. Article 28 requires a binding contract with specific terms. SOC 2 or ISO reports help demonstrate sufficient guarantees and security measures, but they do not replace the DPA.

Among other items: subject matter and duration, nature and purpose, types of personal data and categories of data subjects, and the Article 28(3) obligations (instructions, confidentiality, security, sub-processors, assistance, deletion/return, audits/information).

Only if it fits documented controller instructions or a separate lawful controller purpose with transparency. Silent secondary use of customer personal data commonly breaches Article 28 processor limits.

The contract should set general or specific authorisation. Under general authorisation, inform the controller of intended changes and allow objection as agreed. Keep the public or contractual sub-processor list current.

Often for customer content, yes — but you are typically controller for employee HR data, your billing contacts, and your own website analytics. Role can also be joint controller in edge cases; map roles per processing activity.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: July 2026 · Primary sources linked above