Article 28
Processor
GDPR · Regulation (EU) 2016/679 · Last verified July 2026
Objective
Where processing is carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees, and processing shall be governed by a contract or other legal act that sets out the subject matter, duration, nature, purpose, types of data, obligations, and the Article 28(3) mandatory terms.
Points of focus
- Controllers select processors with sufficient guarantees of Article 32-level measures
- Bind processing to a contract covering Article 28(3) required terms
- Processors act only on documented instructions unless required by law
- Flow down equivalent obligations to sub-processors with prior authorisation rules
- Assist with security, breach notification, DPIAs, and deletion/return at end of service
Implementation notes
Most B2B SaaS companies are processors for customer-uploaded personal data and controllers for their own account and marketing data — Article 28 is the spine of the processor relationship. Maintain a GDPR-ready DPA that includes processing instructions, confidentiality, security measures, sub-processor rules, assistance with data-subject requests, breach cooperation, audit/information rights, and deletion or return at end of service. Diligence new sub-processors (infra, support, AI) before they touch personal data, publish a current sub-processor list, and flow down equivalent terms. Train support and engineering that customer content is processed only on documented instructions — not for unrelated model training or marketing. Pair Article 28 contracts with Article 32 technical measures and transferable evidence (SOC 2, ISO) so 'sufficient guarantees' are both legal and operational.
Audit tip: Produce the DPA template mapped clause-by-clause to Article 28(3), plus one sub-processor onboarding packet (diligence + flow-down + customer notice).
Evidence auditors typically request:
- Signed DPA / Article 28 addendum with customers (controller) or vendors (your processors)
- Sub-processor list with notice/objection mechanism
- Vendor security due diligence records before onboarding processors
- Instructions register or ticket trail for customer deletion/export requests
- SOC 2 / ISO reports used as 'sufficient guarantees' support (not a substitute for the contract)
Common gaps
- MSA without Article 28(3) mandatory processor terms
- Sub-processors added without contract flow-down or customer notice
- Using customer data for product R&D outside documented instructions
- No process to return or delete data after contract end
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 28 | This control |
| ISO 27001 | A.5.19, A.5.20, A.5.21 | Supplier relationships and ICT supply chain |
| SOC 2 | CC9.2 | Vendor risk management |
| HIPAA | 164.308(b), 164.314(a) | Business associate agreements — analogous but distinct regime |
Primary sources
- GDPR Article 28: Regulation (EU) 2016/679, Article 28 — Processor